What changed, and why it matters
This commit adds a temporary debugging step to an Android build workflow. It prints out details about the GitHub environment and pull request, such as repository name, fork status, and commit ID. This is a diagnostic change and does not appear to introduce a security vulnerability on its own, though it does expose some repository metadata in build logs.
No immediate security action required. If this debug job is intended to be temporary, ensure it is removed after troubleshooting to avoid unnecessarily verbose CI logs. Review whether any future additions to the dump could expose sensitive values.
Security signals we found
Workflow context dump added to CI pipeline
No secrets or credentials exposed in the dumped fields
No changes to permissions, secrets, or build commands
Diagnostic-only change with no functional code modifications
Evidence from the diff
The commit adds a new ‘debug-context’ job to .github/workflows/pr_test_build_android.yml. It dumps the full GitHub Actions context JSON and prints several pull_request object fields. The change is additive (+18 lines) and does not modify build logic, secrets handling, or permissions. The dumped context could include repository metadata and PR details, but does not by default include secrets or tokens. If misused, verbose context dumps can aid an attacker in understanding workflow behavior, but no direct exploit path is present here.
Changed components
.github/workflows/pr_test_build_android.ymlInspect captured patch +18 / −0
diff --git a/.github/workflows/pr_test_build_android.yml b/.github/workflows/pr_test_build_android.yml
index 8edb4afc..1ca8d225 100644
--- a/.github/workflows/pr_test_build_android.yml
+++ b/.github/workflows/pr_test_build_android.yml
@@ -10,6 +10,24 @@ defaults:
shell: bash
jobs:
+ debug-context:
+ runs-on: ubuntu-latest
+ steps:
+ - name: "1. Diagnostic Dump"
+ env:
+ # This dumps the entire JSON payload so you can see exactly what GitHub sees
+ GITHUB_CONTEXT: ${{ toJson(github) }}
+ run: echo "$GITHUB_CONTEXT"
+
+ - name: "2. Check Condition Logic"
+ run: |
+ echo "Event Name: ${{ github.event_name }}"
+ echo "Repo Full Name: ${{ github.repository }}"
+ echo "Head Repo: ${{ github.event.pull_request.head.repo.full_name }}"
+ echo "Is Fork: ${{ github.event.pull_request.head.repo.fork }}"
+ echo "PR Number: ${{ github.event.number }}"
+ echo "Head SHA: ${{ github.event.pull_request.head.sha }}"
+ # --------------------------------
# PATH A: Internal PRs (Triggered by standard 'pull_request')
internal-build:
if: |
Why this scored 21/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.