4 ms·
You are wise to be wary. There are some pretty subtle tigers waiting to maul you if you run workflows against untrusted PRs. The way I currently do this is th
by cmsj 5y ago
You are wise to be wary.
There are some pretty subtle tigers waiting to maul you if you run workflows against untrusted PRs.
The way I currently do this is that our workflows run the CI build/test job in the repo of the user proposing the PR and uploads the logs/results as an "Artifact". Our repo waits for that job to complete and then downloads the artifacts and produces a pretty comment with the junit test results on the PR.
However, despite recommending a model like this, GitHub still makes it infuriatingly hard to actually do, and we ended up with all of this crud to be able to get one XML file: https://github.com/Hammerspoon/hammerspoon/blob/master/.github/workflows/ci_testbuild_results.yml#L15 https://github.com/Hammerspoon/hammerspoon/blob/master/.gith...