Skip to content

Mention checkout refs in context expression restriction example#9988

Open
gordonsyme wants to merge 2 commits intomainfrom
gordon/update-safe-context-restriction-expression
Open

Mention checkout refs in context expression restriction example#9988
gordonsyme wants to merge 2 commits intomainfrom
gordon/update-safe-context-restriction-expression

Conversation

@gordonsyme
Copy link
Member

Pipelines can use different sources for checkout and for config. When
this is the case, both of these need to be restricted for the context to
be protected from unreviewed code, or unreviewed config.

Preview your changes:

  • View the Vale linter results, select the ci/circleci: lint job at the bottom of your PR. You will be redirected to the vale/lint job output in CircleCI.
  • Preview your changes, select the ci/circleci: build job at the bottom of your PR and you will be redirected to CircleCI. Select the Artifacts tab and select index.html to open a preview version of the docs site built for your latest commit.

@gordonsyme gordonsyme requested review from a team as code owners February 11, 2026 13:14
@gordonsyme gordonsyme force-pushed the gordon/update-safe-context-restriction-expression branch from c19c721 to 2815b9a Compare February 11, 2026 13:14
Pipelines can use different sources for checkout and for config. When
this is the case, both of these need to be restricted for the context to
be protected from unreviewed code, or unreviewed config.
@gordonsyme gordonsyme force-pushed the gordon/update-safe-context-restriction-expression branch from 2815b9a to 86d2b4f Compare February 11, 2026 13:18
@gordonsyme
Copy link
Member Author

Let's not merge this right now, we don't have consistent pipeline-values between OAuth and GitHub App triggered pipelines.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants