caliper icon indicating copy to clipboard operation
caliper copied to clipboard

What privileges do PR's have when they execute in our github actions ?

Open davidkel opened this issue 3 weeks ago • 0 comments

They should not have access to any publishing tokens, if they do it opens up the possibility of credentials being stolen and they do not need any publishing credentials.

Note sure if PRs need access to any access tokens except read access for github to be able to pull the repo and the PR branch

This is how Shai-Hulud 2.0 came about see https://www.theregister.com/2025/11/28/posthog_shaihulud/

davidkel avatar Nov 28 '25 21:11 davidkel