[ 
https://issues.apache.org/jira/browse/IGNITE-28913?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Anton Vinogradov updated IGNITE-28913:
--------------------------------------
    Summary: GitHub Actions: fork PR checkout refused in pull_request_target 
workflows after actions/checkout v4.4.0 backport  (was: GitHub Actions commit 
checks fail for all fork PRs: checkout refuses pull_request_target)

> GitHub Actions: fork PR checkout refused in pull_request_target workflows 
> after actions/checkout v4.4.0 backport
> ----------------------------------------------------------------------------------------------------------------
>
>                 Key: IGNITE-28913
>                 URL: https://issues.apache.org/jira/browse/IGNITE-28913
>             Project: Ignite
>          Issue Type: Task
>            Reporter: Anton Vinogradov
>            Assignee: Anton Vinogradov
>            Priority: Major
>          Time Spent: 20m
>  Remaining Estimate: 0h
>
> Since the GitHub Actions runner image update (~2026-07-14), actions/checkout 
> refuses to check out fork PR code in a pull_request_target workflow by 
> default (the new "pwn request" guard) and fails with:
>   Refusing to check out fork pull request code from a 'pull_request_target' 
> workflow. ... To opt in, review the risks at 
> https://gh.io/securely-using-pull_request_target and set 
> 'allow-unsafe-pr-checkout: true' on the actions/checkout step.
> As a result every job of commit-check.yml (Code Style, Abandoned Tests, 
> Javadocs; .NET; ducktape) fails on the checkout step for every fork pull 
> request — i.e. for all contributor PRs.
> commit-check.yml uses pull_request_target deliberately (the in-file comment: 
> so the checks also run when the PR conflicts with the base branch) and is 
> already hardened for it: the workflow declares "permissions: contents: read" 
> and documents that no secrets may be added. The untrusted-code risk the new 
> guard protects against is therefore already consciously mitigated.
> Fix: add "allow-unsafe-pr-checkout: true" to each actions/checkout step that 
> checks out github.event.pull_request.head.sha, acknowledging the documented 
> trade-off. (The alternative — switching the trigger to pull_request — would 
> lose the ability to check conflicting PRs, which the workflow explicitly 
> wants.)



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to