What changed, and why it matters
This commit is a routine GitHub Actions workflow tweak. It simplifies when the Android test build runs (only on pull_request events) and changes the runner label to a custom label. There is no user-facing app change, no wallet code change, and no security-relevant behavior visible in the diff.
No security action required. Review the runner label change to ensure the [Linux, amd64, forlinux] self-hosted or custom runners are appropriately secured and maintained, but this is operational hygiene, not a vulnerability.
Security signals we found
No strong security signals were identified.
Evidence from the diff
The patch modifies .github/workflows/pr_test_build_android.yml. It removes pull_request_target triggers and the associated event types, leaving only pull_request. It also changes the job runner from ubuntu-latest to a custom label list [Linux, amd64, forlinux]. These are CI/CD configuration changes; no source code, secrets, permissions, or build logic are altered beyond trigger and runner selection.
Changed components
.github/workflows/pr_test_build_android.ymlInspect captured patch +2 / −6
diff --git a/.github/workflows/pr_test_build_android.yml b/.github/workflows/pr_test_build_android.yml
index 1ca8d225..75dd9486 100644
--- a/.github/workflows/pr_test_build_android.yml
+++ b/.github/workflows/pr_test_build_android.yml
@@ -1,17 +1,13 @@
name: Cake Wallet Android
-on:
- pull_request:
- pull_request_target:
- types: [opened, synchronize, reopened, labeled]
+on: [pull_request]
defaults:
run:
shell: bash
-
jobs:
debug-context:
- runs-on: ubuntu-latest
+ runs-on: [Linux, amd64, forlinux]
steps:
- name: "1. Diagnostic Dump"
env:
Why this scored 15/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.