Skip to content

Enable actions to run without approval for PR contributors #5137

Answered by dureuill
airycanon asked this question in Q&A
Discussion options

You must be logged in to vote

Hello,

Sorry, we cannot approve of your request for security reasons.

The security policy on GitHub Actions prevents possible attacks such as arbitrary code execution, including ones that could target organization secrets or consume CI minutes for malevolent purposes.

Our team is reviewing PRs before launching CI executions.

Just because someone is a contributor doesn't mean they won't become malevolent in the future, it is indeed a common tactic.

This delay can slow down the development process and make it less efficient for contributors.

Running the CI tests locally is good practice that will make it more certain that your code contribution will pass and shorten review time (maintaine…

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by airycanon
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants