pull_request_target in the wild: 60 public workflows, 6 exploitable, and the fixes that actually work
pull_request_target is the GitHub Actions trigger behind a steady stream of and runs it. We ship a rule for exactly that combination. Before trusting it, we measured it Three ingredients, all of them needed: the pull_request_target trigger; a checkout of the pull request's own code (ref: ${{ github.event.pull_request.head.sha }} or .head.ref); a step that executes that code: install scripts, a build, the test suite. With all three, anyone who can open a pull request runs their code with your We sampled 30 public workflows that use pull_request_target. The rule fired on On review, 8 of the 15 w
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in