Harden greetings workflow secret handling#19166
Conversation
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
|
Thanks for your pull request. Before we can look at it, you'll need to add a 'DCO signoff' to your commits. 📝 Please follow instructions in the contributing guide to update your commits with the DCO Full details of the Developer Certificate of Origin can be found at developercertificate.org. The list of commits missing DCO signoff:
DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here. |
✅ Deploy Preview for kubestellarconsole canceled.
|
|
👋 Hey @Copilot — thanks for opening this PR!
This is an automated message. |
📌 Fixes
📝 Summary of Changes
greetings.ymlforwarded all repository secrets into a reusable workflow reachable frompull_request_target. This update removes secret inheritance and aligns the workflow with the existing same-repo guard + pinned-SHA pattern.secrets: inheritfrom thegreetjobpull_request_targetChanges Made
.github/workflows/greetings.ymlto remove inherited secrets@mainto a pinned commit SHApull_request_targetguardChecklist
Please ensure the following before submitting your PR:
git commit -s)Screenshots or Logs (if applicable)
N/A — workflow-only change.
👀 Reviewer Notes
github.tokenautomatically; custom repository secrets are no longer forwarded.Original prompt