feat(chatops): add /command for build test pr in PR - #1355
Conversation
61b8e91 to
fa119c9
Compare
|
@Hugo-Galley Thanks for the PR. I will take a look soon. Hopefully this is fine for you. |
|
I fixed the trivy issue already in a different PR. So it looks good so far. |
|
Hi @Hugo-Galley could you rebase? |
|
Hi @perber, Sorry, I’m currently on vacation and don’t have access to my PC. I won’t be able to work on this until early September. I wanted to open the PR before leaving so it was already available for review. I’ll rebase it and address any feedback once I’m back in September. Thanks for your patience! |
|
Hi @Hugo-Galley, Enjoy your vacation. |
|
Hi @Hugo-Galley, I think we should built it only when a 'maintainer' is using this command. |
fa119c9 to
3bb0157
Compare
|
Hi @perber, what do you think about using “maintainer” here? Do you mean only repository owners, or also regular contributors and approving contributors? I’m not sure which ones you’re referring to. |
|
Hi @Hugo-Galley, |
|
@perber No worries at all, took me a while to reply as well ;). Sounds good to me. I'll restrict creation to the owner only. Nothing is set in stone anyway, we can always add it back later if we change our minds :) |
3bb0157 to
ea5b73d
Compare
|
@perber i push fix. It's ok for you ? |
Removed instructions for building a test image from the PR template.
…ing PR-controlled Makefile - /create-test-image no longer tags :latest on ghcr.io — it inlines the docker buildx build/push command instead of calling `make docker-build-publish`, so the PR's own Makefile is never executed on the runner with a packages:write token (pwn-request pattern: the checked-out PR code could otherwise redefine that Make target to exfiltrate the token that docker/login-action already wrote to disk). - Broaden the trigger gate from author_association == 'OWNER' to also allow COLLABORATOR, matching "owner or someone with write access to the project" rather than literally only the single OWNER association. - Add trailing newlines to both new workflow files.
…rite token pull_request (non-target) events from a fork PR get a read-only GITHUB_TOKEN regardless of the permissions: block, unless the repo has opted in to write tokens for fork PRs (off by default). Since this job never checks out or executes PR code — it only reads the PR number from the trusted event payload to delete matching ghcr.io package versions — pull_request_target is the safe way to get a write token here without the checkout-and-run risk that pattern normally carries.
Related issue
This PR references issue #1280.
What changed
/create-test-image.Checklist
npm run formatinui/leafwiki-ui(and ine2eif e2e tests changed)