Repository navigation
Conversation
Refs: google-gemini#28336 - Removes the unsafe eval-pr.yml which used pull_request_target - Replaces with eval-pr-build.yml (pull_request) for untrusted build - Replaces with eval-pr-run.yml (workflow_run) for trusted execution using build artifacts
|
Note Gemini is unable to generate a summary for this pull request due to the file types involved not being currently supported. |
|
📊 PR Size: size/L
|
- Pin actions/upload-artifact to v4 hash
- Fix template injections by moving ${{ }} interpolations to env variables
- Add zizmor ignore for safe workflow_run trigger
|
Hi there! Thank you for your interest in contributing to Gemini CLI. To ensure we maintain high code quality and focus on our prioritized roadmap, we only guarantee review and consideration of pull requests for issues that are explicitly labeled as 'help wanted'. This PR will be closed in 7 days if it remains without that designation. We encourage you to find and contribute to existing 'help wanted' issues in our backlog! Thank you for your understanding. |
|
This pull request is being closed as it has been open for 14 days without a 'help wanted' designation. We encourage you to find and contribute to existing 'help wanted' issues in our backlog! Thank you for your understanding. |
This PR fixes a critical security issue where untrusted fork code could execute in a privileged pull_request_target context (Issue #28336). It splits the eval workflow into a secure pull_request build step and a trusted workflow_run execution step.