What changed, and why it matters
This commit only edits a GitHub Actions workflow file used for testing pull requests. It renames comments, reformats YAML syntax, and changes the runner label from 'ubuntu-latest' to a custom label '[Linux, amd64, forlinux]'. There is no change to application code, wallet logic, cryptography, or user data handling.
No action required. If the custom runner label is intended for a new self-hosted runner, verify that runner's access controls and isolation separately, but that is outside the scope of this commit diff.
Security signals we found
No strong security signals were identified.
Evidence from the diff
The diff modifies .github/workflows/pr_test_build_android.yml. Changes are cosmetic/operational: comment rewording, YAML block scalar style changes (| to >), removal of explanatory comments, and a runner label change from ubuntu-latest to a custom self-hosted or labeled runner array. The workflow still uses pull_request_target for external forks and passes secrets via secrets: inherit. No security-relevant behavior is introduced or removed in this patch.
Changed components
.github/workflows/pr_test_build_android.ymlInspect captured patch +12 / −12
diff --git a/.github/workflows/pr_test_build_android.yml b/.github/workflows/pr_test_build_android.yml
index d860e237..150aa86d 100644
--- a/.github/workflows/pr_test_build_android.yml
+++ b/.github/workflows/pr_test_build_android.yml
@@ -6,15 +6,15 @@ on:
pull_request_target:
jobs:
+
debug-context:
+ runs-on: [Linux, amd64, forlinux]
defaults:
run:
shell: bash
- runs-on: ubuntu-latest
steps:
- name: "1. Diagnostic Dump"
env:
- # This dumps the entire JSON payload so you can see exactly what GitHub sees
GITHUB_CONTEXT: ${{ toJson(github) }}
run: echo "$GITHUB_CONTEXT"
@@ -27,27 +27,27 @@ jobs:
echo "PR Number: ${{ github.event.number }}"
echo "Head SHA: ${{ github.event.pull_request.head.sha }}"
- # PATH A: Internal PRs (Triggered by standard 'pull_request')
+ # -----------------------------------------
+ # PATH A: Internal PRs
internal-build:
- if: |
- github.event_name == 'pull_request' &&
+ if: >
+ github.event_name == 'pull_request' &&
github.event.pull_request.head.repo.fork == false
uses: ./.github/workflows/reusable-build.yml
with:
ref: ${{ github.event.pull_request.head.sha }}
pr_number: ${{ github.head_ref || github.ref_name }}
- secrets: inherit # Passes all secrets automatically
+ secrets: inherit
- # PATH B: External Forks (Triggered by 'pull_request_target' for security)
+ # -----------------------------------------
+ # PATH B: External Fork PRs
external-build:
- if: |
- github.event_name == 'pull_request_target' &&
+ if: >
+ github.event_name == 'pull_request_target' &&
github.event.pull_request.head.repo.fork == true
-
environment: external_contributors
-
uses: ./.github/workflows/reusable-build.yml
with:
ref: ${{ github.event.pull_request.head.sha }}
pr_number: ${{ github.head_ref || github.ref_name }}
- secrets: inherit
\ No newline at end of file
+ secrets: inherit
Why this scored 15/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.