logoalt Hacker News

ZeWakayesterday at 11:41 PM1 replyview on HN

they probably used the publish token in a pull-request-target workflow or something?


Replies

ghost_peppertoday at 12:05 AM

yes, they used pull_request_target for a benchmarking suite. github has a huge warning saying to never use pull_request_target to run user code, but this is just going to keep happening

show 2 replies