Skip to content

Conversation

@singiamtel
Copy link
Contributor

@singiamtel singiamtel commented Jan 27, 2026

I think this job is vulnerable. I haven't tried to exploit myself, but I think a malicious PR could replace o2_linter.py with arbitrary code

In general it's very easy to make unsafe workflows with pull_request_target (e.g. https://www.sysdig.com/blog/insecure-github-actions-found-in-mitre-splunk-and-other-open-source-repositories#pullrequesttarget-abuse). I think it shouldn't be hard to rewrite it to use pull_request

@github-actions
Copy link

O2 linter results: ❌ 0 errors, ⚠️ 0 warnings, 🔕 0 disabled

@github-actions github-actions bot changed the title Temporarily disable O2linter job [Infrastructure] Temporarily disable O2linter job Jan 27, 2026
@ktf ktf merged commit 72c073c into master Jan 27, 2026
8 of 9 checks passed
@ktf ktf deleted the o2-linter branch January 27, 2026 17:03
monamelop pushed a commit to monamelop/O2Physics that referenced this pull request Jan 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Development

Successfully merging this pull request may close these issues.

3 participants