Skip to content

Commit 008e539

Browse files
authored
ci: remove pull_request_target trigger from release-drafter (#178)
Why === The recent [TanStack NPM supply-chain compromise](https://tanstack.com/blog/npm-supply-chain-compromise-postmortem) exploited a `pull_request_target` workflow. Per Replit security policy, we are removing `pull_request_target` triggers from all Replit-owned public repos as a precaution, even where the current use looks safe. Slack thread: https://replit.slack.com/archives/C03FS477T17/p1778588219046429 What changed ============ Removed the `pull_request_target` trigger block from `.github/workflows/release-drafter.yml`. No other changes. Note: the autolabeler will no longer run on PRs from forks. Release notes are still drafted on push to `main`, so the core release-drafter behavior is preserved. Test plan ========= Static change to a workflow trigger; no runtime test plan. The remaining `push` (to `main`) and `pull_request` triggers continue to run release-drafter as before. Revertibility ============= Safe to revert — single-file workflow change, no data or schema impact. ~ written by Zerg 👾 ([ravaging-mothership-61f2](https://zerg.zergrush.dev/chat?id=ravaging-mothership-61f2))
1 parent af775fc commit 008e539

1 file changed

Lines changed: 0 additions & 3 deletions

File tree

‎.github/workflows/release-drafter.yml‎

Lines changed: 0 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -10,9 +10,6 @@ on:
1010
pull_request:
1111
# Only following types are handled by the action, but one can default to all as well
1212
types: [opened, reopened, synchronize]
13-
# pull_request_target event is required for autolabeler to support PRs from forks
14-
pull_request_target:
15-
types: [opened, reopened, synchronize]
1613

1714
permissions:
1815
contents: read

0 commit comments

Comments
 (0)