Skip to content

Conversation

@clue
Copy link
Owner

@clue clue commented Sep 14, 2021

This changeset fixes the CI script to actually check out the PR head and use the DEPLOY_KEY secret only for cloning Framework X.

Without these changes, we only run tests against the current main branch and do not actually test the PR contents (noticed this in https://github.com/clue-engineering/justkanban/pull/35 (private)).

Builds on top of #10, #9 and #7
Refs https://securitylab.github.com/research/github-actions-preventing-pwn-requests/, https://github.blog/2020-08-03-github-actions-improvements-for-fork-and-pull-request-workflows/, https://getcomposer.org/doc/articles/authentication-for-private-packages.md#github-oauth, https://getcomposer.org/doc/03-cli.md#composer-auth

@clue clue added bug Something isn't working new feature New feature or request labels Sep 14, 2021
@SimonFrings SimonFrings merged commit 29abe9f into clue:main Sep 15, 2021
@clue clue deleted the ci branch November 21, 2021 11:43
@clue clue mentioned this pull request Nov 23, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working new feature New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants