What changed, and why it matters
This commit changes a GitHub Actions workflow file for Android test builds. It removes automatic triggers for regular pushes and for pull_request_target events, leaving only standard pull_request triggers. It also adds a large commented-out block showing an alternative workflow path for external fork pull requests. The change appears to be a debugging or hardening adjustment to how CI runs, not a code change in the app itself. There is no direct evidence this fixes a security vulnerability, but narrowing CI triggers can reduce attack surface for supply-chain-style abuse.
Treat as a low-risk CI hardening/debugging change. Review whether the commented-out external fork build path is intended to be enabled, and if so, ensure it uses strict environment protection rules, does not pass writable tokens to untrusted code, and limits secrets exposure. No urgent app-level action is indicated by this commit alone.
Security signals we found
Removal of pull_request_target trigger from CI workflow
Removal of push trigger from CI workflow
Commented-out external fork build job using pull_request_target and secrets inheritance
Commit message 'debugging workflow' provides no security context
Evidence from the diff
The diff modifies .github/workflows/pr_test_build_android.yml. It removes ‘push:’ and ‘pull_request_target:’ from the ‘on:’ section so the workflow now triggers only on ‘pull_request:’. A commented-out ‘external-build’ job is added that would run on pull_request_target for fork PRs using an ‘external_contributors’ environment and inherited secrets. The commit message is simply ‘debugging workflow’. No application code, secrets, or build scripts are changed. The change is consistent with reducing risky CI triggers (pull_request_target is a known high-risk event for CI/CD attacks on forks), but the patch is partial because the alternative path is only commented out.
Changed components
.github/workflows/pr_test_build_android.ymlInspect captured patch +12 / −3
diff --git a/.github/workflows/pr_test_build_android.yml b/.github/workflows/pr_test_build_android.yml
index 857c7843..a15062c8 100644
--- a/.github/workflows/pr_test_build_android.yml
+++ b/.github/workflows/pr_test_build_android.yml
@@ -1,9 +1,7 @@
name: Cake Wallet Android
on:
- push:
pull_request:
- pull_request_target:
jobs:
@@ -39,4 +37,15 @@ jobs:
pr_number: ${{ github.head_ref || github.ref_name }}
secrets: inherit
-
+# # -----------------------------------------
+# # PATH B: External Fork PRs
+# external-build:
+# if: >
+# github.event_name == 'pull_request_target' &&
+# github.event.pull_request.head.repo.fork == true
+# environment: external_contributors
+# uses: ./.github/workflows/reusable-build.yml
+# with:
+# ref: ${{ github.event.pull_request.head.sha }}
+# pr_number: ${{ github.head_ref || github.ref_name }}
+# secrets: inherit
Why this scored 17/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.