Skip to content

CI Workflow Fork Restriction: 1 issue found #21

@hekkos-app

Description

@hekkos-app

Hekkos found 1 CI Workflow Fork Restriction configuration issue in this repository.

This is part of the main security audit.

Issue details
  • Issue 1: Workflow approval is not required for all external contributors - fork PRs can trigger workflows without approval

Why this matters

CI workflow fork restrictions help prevent untrusted code execution from forked repositories. This ensures:

  • Workflows from fork PRs cannot run without approval
  • Reduces risk of malicious code executing in your CI environment
  • Protects secrets and sensitive operations from untrusted contributors
  • Important for public repositories where anyone can fork

How to fix

  1. Navigate to Settings > Actions > General
  2. Under Fork pull request workflows, select Require approval for all outside collaborators
  3. Review and adjust workflow permissions as needed

Documentation:

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions