macadmins / sofa

SOFA | A MacAdmin's Simple Organized Feed for Apple Software Updates
https://sofa.macadmins.io
Apache License 2.0
162 stars 27 forks source link

SOFA PRs may be able to be abused by non-approved authors #103

Open erikng opened 3 months ago

erikng commented 3 months ago

The current github action has no safety when running on branches or PRs. I rogue PR may be able to abuse this action and steal our credentials.

erikng commented 3 months ago

so it turns out this may not be an issue

https://github.com/orgs/community/discussions/26374

and it's not even possible to fix when using the cron option. We just need to be careful if we ever add other github actions.