Skip to content

Hardening for pull_request_target usage #18

@S4tvara

Description

@S4tvara

Audit actions to avoid checking out untrusted code; document security notes and safe patterns.\n\nAcceptance:\n- Docs callouts added\n- Code avoids unsafe operations

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions