What changed, and why it matters
This commit changes the Android CI workflow so that pull requests from outside contributors run using 'pull_request_target' and a dedicated 'external_contributors' environment. That combination is a well-known GitHub Actions anti-pattern: it can let a malicious pull request steal repository secrets or modify the repository, because the workflow runs in the context of the base repository with access to its secrets, while still processing code from the pull request. The change itself is small, but the security risk is real if the workflow later checks out or runs untrusted PR code.
Review the full workflow to confirm it does not check out or execute code from the pull request head. If it does, revert to 'pull_request' for untrusted builds, or use a two-workflow design where an unprivileged 'pull_request' workflow uploads artifacts and a privileged 'workflow_run' workflow handles signing/secrets. Require manual approval for the external_contributors environment and restrict secrets to that environment only if the trigger is retained.
Security signals we found
Use of pull_request_target trigger for CI that may process untrusted PR code
Addition of an external_contributors environment, signaling awareness of untrusted contributors
Potential secret exfiltration if PR head checkout is performed
Potential supply-chain/build artifact tampering if build runs untrusted code with repository secrets
Evidence from the diff
The diff switches the workflow trigger from ‘pull_request’ to ‘pull_request_target’ and adds an ‘environment: external_contributors’ job setting. ‘pull_request_target’ runs the workflow with write permissions and access to repository secrets, using the base branch’s workflow file. If the job later checks out the PR head (e.g., via actions/checkout with ref: github.event.pull_request.head.sha) or executes code from the PR, a malicious external contributor can exfiltrate secrets, poison the build cache, or push to the repository. The added environment may gate approvals, but it does not remove the unsafe trigger by itself. The supplied diff does not show whether the workflow checks out untrusted code, so the risk is conditional on that subsequent behavior.
Changed components
.github/workflows/pr_test_build_android.ymlInspect captured patch +2 / −1
diff --git a/.github/workflows/pr_test_build_android.yml b/.github/workflows/pr_test_build_android.yml
index e83cd0ac..72915eb9 100644
--- a/.github/workflows/pr_test_build_android.yml
+++ b/.github/workflows/pr_test_build_android.yml
@@ -1,6 +1,6 @@
name: Cake Wallet Android
-on: [pull_request]
+on: [pull_request_target]
defaults:
run:
@@ -8,6 +8,7 @@ defaults:
jobs:
PR_test_build:
runs-on: [Linux, amd64, android]
+ environment: external_contributors
container:
image: ghcr.io/cake-tech/cake_wallet:debian13-flutter3.32.0-ndkr28-go1.24.1-ruststablenightly
env:
Why this scored 53/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.