Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
26 changes: 26 additions & 0 deletions .github/workflows/verify.yml
Original file line number Diff line number Diff line change
Expand Up @@ -79,3 +79,29 @@ jobs:
run: |
python3 tools/test_check_version_floors.py
python3 tools/check-version-floors.py

# Includes a dry run of the next release against the real CHANGELOG.md and
# changelog.d/, so a fragment or marker that would break it fails here first.
- name: Changelog collect (stdlib only)
run: python3 tools/test_changelog_collect.py

# Every PR that added its entry under the shared `## [Unreleased]` heading
# conflicted with every other open PR that did the same. Entries go in
# changelog.d/ (one file each); only a release/* branch rewrites CHANGELOG.md.
changelog-fragments:
name: CHANGELOG.md is edited only by releases
if: github.event_name == 'pull_request' && !startsWith(github.head_ref, 'release/')

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kody code-review Bug medium

Authorization bypass in changelog-fragments job condition: the release exemption checks only github.head_ref, which the PR author controls, including on forks where the base repo's branch rules do not apply. When a contributor opens a PR from a fork branch named release/fix that edits CHANGELOG.md directly, the job is skipped, and because a skipped job reports as passing, the required check does not block the merge. Fix: also require github.event.pull_request.head.repo.full_name == github.repository so the exemption applies only to branches in this repository.

if: github.event_name == 'pull_request' && !(startsWith(github.head_ref, 'release/') && github.event.pull_request.head.repo.full_name == github.repository)
Prompt for LLM

File .github/workflows/verify.yml:

Line 88:

Authorization bypass in changelog-fragments job condition: the release exemption checks only `github.head_ref`, which the PR author controls, including on forks where the base repo's branch rules do not apply. When a contributor opens a PR from a fork branch named `release/fix` that edits `CHANGELOG.md` directly, the job is skipped, and because a skipped job reports as passing, the required check does not block the merge. Fix: also require `github.event.pull_request.head.repo.full_name == github.repository` so the exemption applies only to branches in this repository.

Suggested Code:

if: github.event_name == 'pull_request' && !(startsWith(github.head_ref, 'release/') && github.event.pull_request.head.repo.full_name == github.repository)

Talk to Kody by mentioning @kody

Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.

​

​

runs-on: ubuntu-latest
steps:
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
with:
fetch-depth: 2
persist-credentials: false

- name: Changelog entries are fragments in changelog.d/
run: |
# HEAD is GitHub's test merge of the PR into its base, so HEAD^1 is the base tip.
if ! git diff --quiet HEAD^1 HEAD -- CHANGELOG.md; then
echo "::error file=CHANGELOG.md::Put the entry in a new file under changelog.d/ instead (see changelog.d/README.md). CHANGELOG.md changes only on a release/* branch."
exit 1
fi
Loading
Loading