lupyuen commented on PR #19075:
URL: https://github.com/apache/nuttx/pull/19075#issuecomment-4686673563

   Hi @zhangning21: I'm sorry that we have to close this PR because:
   1. NuttX Maintainers feel that embedding PR Metadata (like `depends-on`) 
inside the PR Body, might confuse PR Authors and PR Reviewers: (1) Editing the 
PR Metadata won't trigger a rebuild (2) Errors in the PR Metadata are silently 
ignored
   2. NuttX CI Team doesn't have the awk / sed skills to maintain the proposed 
Shell Script that safely parses and extracts the PR Metadata from the PR Body. 
Which might lead to Script Injection Attacks in future updates.
   
   I'm also sorry for your time wasted in preparing this meticulous PR. Perhaps 
in future, you could create a NuttX Issue first, then assign it to me for 
discussion, so we can agree on the best solution?
   
   I hope you understand that ASF Infrastructure Team is closely watching our 
usage of GitHub Actions. They nearly banned NuttX Project twice from using 
GitHub Actions, due to overuse and security concerns. Thanks :-)


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to