Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore: update actions/add-to-project digest to 0a99102 #3722

Merged
merged 2 commits into from
Jul 17, 2023

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Jul 11, 2023

Mend Renovate

This PR contains the following updates:

Package Type Update Change
actions/add-to-project action digest a800ee6 -> 0a99102

Configuration

📅 Schedule: Branch creation - "after 10pm,before 5:00am" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate. View repository job log here.

@renovate renovate bot added the dependencies Updates a dependency label Jul 11, 2023
@bpmn-io-tasks bpmn-io-tasks bot added the needs review Review pending label Jul 11, 2023
@renovate renovate bot changed the title chore: update actions/add-to-project digest to 87ad3e8 chore: update actions/add-to-project digest to 36f5795 Jul 11, 2023
@renovate renovate bot force-pushed the renovate/actions-add-to-project-digest branch from 2c3faf5 to 43f1edf Compare July 11, 2023 15:43
@renovate renovate bot changed the title chore: update actions/add-to-project digest to 36f5795 chore: update actions/add-to-project digest to 0a99102 Jul 14, 2023
@renovate renovate bot force-pushed the renovate/actions-add-to-project-digest branch from 43f1edf to 91c8b9c Compare July 14, 2023 17:04
@renovate
Copy link
Contributor Author

renovate bot commented Jul 17, 2023

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

Warning: custom changes will be lost.

@nikku nikku requested review from a team, smbea and barmac and removed request for a team July 17, 2023 06:58
Copy link
Collaborator

@barmac barmac left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cross-posting my stance on this:

Generally, depending on a tag of an external repo is considered to be less secure. If an evil actor can make their commit into the repo with that tag, that means they can automatically hack our system.
However, the add-to-project action is part of the official GitHub actions org, and we already depend on tags of other repositories within this org, e.g. https://github.com/camunda/camunda-modeler/blob/develop/.github/workflows/CI.yml#L12. So depending on a tag of add-to-project would be a consequence of the trust we have already put into that org.
IMO it's OK how we do it, and I'd rather focus on minimazing the potential impact of the action being compromised. In that specific case, that would mean the GH token passed to the workflow should have only the permissions required to perform the specific action.

@barmac barmac merged commit ab40147 into develop Jul 17, 2023
11 checks passed
@barmac barmac deleted the renovate/actions-add-to-project-digest branch July 17, 2023 08:14
@bpmn-io-tasks bpmn-io-tasks bot removed the needs review Review pending label Jul 17, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Updates a dependency
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants