sbp opened a new issue, #1311:
URL: https://github.com/apache/tooling-trusted-releases/issues/1311

   If a project uses a GitHub repository which is known to ATR, we could check 
for the existence of `pull_request_target` in any of its workflows and then 
either warn or block. This check would be similar to the one that checks the 
structure of source artifacts relative to GitHub source trees: since they both 
require pulling the tree from GitHub, that part could be abstracted out 
somehow. It may even be useful to do it as part of quarantine.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to