Skip to content

Remove vulnerable PR-comment artifact pattern - #61

Merged
erikrikarddaniel merged 1 commit into
masterfrom
patch
Jul 24, 2026
Merged

Remove vulnerable PR-comment artifact pattern#61
erikrikarddaniel merged 1 commit into
masterfrom
patch

Conversation

@mashehu

@mashehu mashehu commented Jul 24, 2026

Copy link
Copy Markdown
Contributor

Security patch

This PR applies a security fix included in nf-core/tools 4.0.3 for a potential exploit in the GitHub Actions workflows that post comments on pull requests.

For details, see the related security advisory: https://nf-co.re/advisories/pr-comment-workflow-vulnerability

The fix must be merged into the default branch to take effect. Please merge this PR as soon as possible.

These changes only affect CI workflows, so merging them into the default branch does not require a new pipeline release.

@nf-core-bot

Copy link
Copy Markdown
Member

Warning

Newer version of the nf-core template is available.

Your pipeline is using an old version of the nf-core template: 4.0.2.
Please update your pipeline to the latest version.

For more documentation on how to update your pipeline, please see the Synchronisation documentation.

@github-actions

Copy link
Copy Markdown

nf-core pipelines lint overall result: Passed ✅ ⚠️

Posted for pipeline commit 9f0716b

+| ✅ 228 tests passed       |+
#| ❔  10 tests were ignored |#
!| ❗   3 tests had warnings |!
Details

❗ Test warnings:

❔ Tests ignored:

  • files_exist - File is ignored: conf/igenomes.config
  • files_exist - File is ignored: .github/workflows/linting_comment.yml
  • nextflow_config - Config variable ignored: params.input
  • files_unchanged - File ignored due to lint config: .gitattributes
  • files_unchanged - File ignored due to lint config: .github/workflows/branch.yml
  • files_unchanged - File does not exist: .github/workflows/linting_comment.yml
  • files_unchanged - File ignored due to lint config: .github/workflows/linting.yml
  • files_unchanged - File ignored due to lint config: assets/nf-core-phyloplace_logo_light.png
  • files_unchanged - File ignored due to lint config: docs/images/nf-core-phyloplace_logo_light.png
  • files_unchanged - File ignored due to lint config: docs/images/nf-core-phyloplace_logo_dark.png

✅ Tests passed:

Run details

  • nf-core/tools version 4.0.2
  • Run at 2026-07-24 14:30:28

@erikrikarddaniel
erikrikarddaniel merged commit 70348d5 into master Jul 24, 2026
59 of 60 checks passed
@erikrikarddaniel
erikrikarddaniel deleted the patch branch July 24, 2026 15:49
erikrikarddaniel added a commit that referenced this pull request Jul 28, 2026
Resolves .nf-core.yml conflict between master's PR-comment security
hotfix (#61, ignore entries for the hand-patched workflow files) and
dev's newer 4.0.3 template sync / 2.1.0 version bump: keep the union of
both branches' lint-ignore entries and dev's newer version fields.
Verified clean with `nf-core pipelines lint --release`.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants