What changed, and why it matters
This commit changes a GitHub Actions workflow file. It adds triggers for pull requests and pull_request_target events, switches the runner label, and adds spacing. The pull_request_target trigger is notable because it can run workflows in the context of the base repository when a pull request comes from a fork, which can be risky if secrets or write permissions are exposed to untrusted code. However, this commit also adds a guard limiting that trigger to fork PRs and routes it through an 'external_contributors' environment, which suggests an attempt to isolate untrusted builds. There is no direct evidence in the diff of a vulnerability being introduced or fixed.
Review the reusable-build.yml workflow and the 'external_contributors' environment configuration to ensure secrets and write permissions are not granted to untrusted fork code. Verify that pull_request_target is necessary and that checkout/actions do not mix base-ref and head-ref contexts unsafely. Consider whether the switch from self-hosted runners to ubuntu-latest affects build integrity or signing steps.
Security signals we found
pull_request_target trigger added
workflow now runs on fork pull requests
runner changed from self-hosted labels to GitHub-hosted ubuntu-latest
environment 'external_contributors' used for fork PRs
commit message is non-descriptive ('debugging workflow')
Evidence from the diff
The diff modifies .github/workflows/pr_test_build_android.yml. Changes: (1) expands workflow triggers from push-only to push, pull_request, and pull_request_target; (2) changes runs-on from a custom self-hosted label [Linux, amd64, forlinux] to ubuntu-latest; (3) adds blank lines around the pull_request_target conditional job. The pull_request_target job is gated to fork PRs and uses an environment named external_contributors. pull_request_target runs with base repository permissions/secrets, so misuse can lead to secret exfiltration or repository compromise if the reusable workflow or environment is misconfigured. The switch to ubuntu-latest removes reliance on a self-hosted runner label, which could reduce self-hosted runner poisoning risk but also changes trust boundaries. The commit title/message ‘debugging workflow’ gives no security context.
Changed components
.github/workflows/pr_test_build_android.ymlInspect captured patch +7 / −2
diff --git a/.github/workflows/pr_test_build_android.yml b/.github/workflows/pr_test_build_android.yml
index 92d6e63f..8cddc508 100644
--- a/.github/workflows/pr_test_build_android.yml
+++ b/.github/workflows/pr_test_build_android.yml
@@ -1,13 +1,16 @@
name: Cake Wallet Android
-on: [push]
+on:
+ push:
+ pull_request:
+ pull_request_target:
jobs:
debug-context:
defaults:
run:
shell: bash
- runs-on: [Linux, amd64, forlinux]
+ runs-on: ubuntu-latest
steps:
- name: "1. Diagnostic Dump"
env:
@@ -40,7 +43,9 @@ jobs:
if: |
github.event_name == 'pull_request_target' &&
github.event.pull_request.head.repo.fork == true
+
environment: external_contributors
+
uses: ./.github/workflows/reusable-build.yml
with:
ref: ${{ github.event.pull_request.head.sha }}
Why this scored 39/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.