kszucs commented on pull request #7028:
URL: https://github.com/apache/arrow/pull/7028#issuecomment-618944665


   There is another security constraint about this approach: anyone can trigger 
a rebase on the PR not just the participants. To resolve that you need to check 
`author_association` in the event payload, see the python bot's implementation 
[here](https://github.com/apache/arrow/blob/master/dev/archery/archery/bot.py#L179).


----------------------------------------------------------------
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

For queries about this service, please contact Infrastructure at:
us...@infra.apache.org


Reply via email to