From 00ec97665c86dfc413205efec3768110fd782068 Mon Sep 17 00:00:00 2001 From: Cal Date: Wed, 3 Sep 2025 12:33:40 -0700 Subject: [PATCH 1/3] Attempt to dispatch on all pushes. --- .github/workflows/prove-dispatch-works.yaml | 30 +++++++++++++++++++++ 1 file changed, 30 insertions(+) create mode 100644 .github/workflows/prove-dispatch-works.yaml diff --git a/.github/workflows/prove-dispatch-works.yaml b/.github/workflows/prove-dispatch-works.yaml new file mode 100644 index 0000000..d78c18e --- /dev/null +++ b/.github/workflows/prove-dispatch-works.yaml @@ -0,0 +1,30 @@ +# A basic workflow to dispatch another workflow +name: Dispatch Workflow + +# Controls when the action will run. +# This workflow now runs on pushes AND pull requests +on: [push, pull_request] + +# A workflow run is made up of one or more jobs that can run sequentially or in parallel +jobs: + # This workflow contains a single job called "print" + print: + # The type of runner that the job will run on + runs-on: ubuntu-latest + + # Steps represent a sequence of tasks that will be executed as part of the job + steps: + # This step checks out a copy of your repository + # so that git and gh commands have context. + - name: Checkout repository + uses: actions/checkout@v4 + + - name: Trigger the vulnerable workflow dispatch + env: + GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} + run: | + # We'll use a simple string for this test + test_str='Hello from the trigger workflow!' + echo "Triggering CTF workflow with payload: $test_str" + # Use double quotes to ensure the variable expands correctly. + gh workflow run workflow-dispatch.yaml --ref ${{ github.ref }} -f message="$test_str" \ No newline at end of file From ad2c897425e102c711800b161fe971056799a62a Mon Sep 17 00:00:00 2001 From: Cal Date: Wed, 3 Sep 2025 12:59:57 -0700 Subject: [PATCH 2/3] Add permissions for action to trigger other workflows. --- .github/workflows/prove-dispatch-works.yaml | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/.github/workflows/prove-dispatch-works.yaml b/.github/workflows/prove-dispatch-works.yaml index d78c18e..d6c976a 100644 --- a/.github/workflows/prove-dispatch-works.yaml +++ b/.github/workflows/prove-dispatch-works.yaml @@ -12,6 +12,11 @@ jobs: # The type of runner that the job will run on runs-on: ubuntu-latest + # This block grants the GITHUB_TOKEN the permission + # to trigger other workflows. + permissions: + actions: write + # Steps represent a sequence of tasks that will be executed as part of the job steps: # This step checks out a copy of your repository From d854e2f6b191553f86513c13895d493670b10011 Mon Sep 17 00:00:00 2001 From: Cal Date: Wed, 3 Sep 2025 13:04:53 -0700 Subject: [PATCH 3/3] Only run on pull requests. --- .github/workflows/prove-dispatch-works.yaml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/prove-dispatch-works.yaml b/.github/workflows/prove-dispatch-works.yaml index d6c976a..b134f92 100644 --- a/.github/workflows/prove-dispatch-works.yaml +++ b/.github/workflows/prove-dispatch-works.yaml @@ -3,7 +3,7 @@ name: Dispatch Workflow # Controls when the action will run. # This workflow now runs on pushes AND pull requests -on: [push, pull_request] +on: [pull_request] # A workflow run is made up of one or more jobs that can run sequentially or in parallel jobs: @@ -32,4 +32,4 @@ jobs: test_str='Hello from the trigger workflow!' echo "Triggering CTF workflow with payload: $test_str" # Use double quotes to ensure the variable expands correctly. - gh workflow run workflow-dispatch.yaml --ref ${{ github.ref }} -f message="$test_str" \ No newline at end of file + gh workflow run workflow-dispatch.yaml --ref ${{ github.event.pull_request.head.ref }} -f message="$test_str" \ No newline at end of file