Skip to content

SonarCloud Analysis #5561

SonarCloud Analysis

SonarCloud Analysis #5561

Triggered via workflow run July 23, 2026 08:05
@maoyouaamaoyouaa
completed 1512515
Status Failure
Total duration 10m 54s
Artifacts

sonar.yaml

on: workflow_run
Upload to SonarCloud
7s
Upload to SonarCloud
Fit to window
Zoom out
Zoom in

Annotations

1 error
Upload to SonarCloud
Refusing to check out fork pull request code from a 'workflow_run' workflow. This workflow runs with the base repository's GITHUB_TOKEN, secrets, default-branch cache scope, and runner access. Fetching and executing a fork's code in that trusted context commonly leads to "pwn request" vulnerabilities. To opt in, review the risks at https://gh.io/securely-using-pull_request_target and set 'allow-unsafe-pr-checkout: true' on the actions/checkout step.