Commit 008e539
authored
ci: remove pull_request_target trigger from release-drafter (#178)
Why
===
The recent [TanStack NPM supply-chain
compromise](https://tanstack.com/blog/npm-supply-chain-compromise-postmortem)
exploited a `pull_request_target` workflow. Per Replit security policy,
we are removing `pull_request_target` triggers from all Replit-owned
public repos as a precaution, even where the current use looks safe.
Slack thread:
https://replit.slack.com/archives/C03FS477T17/p1778588219046429
What changed
============
Removed the `pull_request_target` trigger block from
`.github/workflows/release-drafter.yml`. No other changes.
Note: the autolabeler will no longer run on PRs from forks. Release
notes are still drafted on push to `main`, so the core release-drafter
behavior is preserved.
Test plan
=========
Static change to a workflow trigger; no runtime test plan. The remaining
`push` (to `main`) and `pull_request` triggers continue to run
release-drafter as before.
Revertibility
=============
Safe to revert — single-file workflow change, no data or schema impact.
~ written by Zerg 👾
([ravaging-mothership-61f2](https://zerg.zergrush.dev/chat?id=ravaging-mothership-61f2))1 parent af775fc commit 008e539
1 file changed
Lines changed: 0 additions & 3 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
10 | 10 | | |
11 | 11 | | |
12 | 12 | | |
13 | | - | |
14 | | - | |
15 | | - | |
16 | 13 | | |
17 | 14 | | |
18 | 15 | | |
| |||
0 commit comments