You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Piloting in retina-tracker (#5, a PUBLIC repo), automated security review flagged HIGH on the workflow assets:
claude.yml's @claude trigger is invokable by ANY commenter, now write-scoped — needs an author_association (OWNER/MEMBER/COLLABORATOR) guard on the if: gate. Applied in retina-tracker; propose a public-repo template variant.
pull-requests: write on the review workflow's pull_request trigger is fork-exploitable on public repos; document pull_request_target + author allow-list guidance.
SHA-pin the marketplace ref in settings.json and third-party actions (astral-sh/setup-uv@v5, anthropics/claude-code-action@v1); add top-level permissions: { contents: read } to ci.yml.
Refs Pilot: adopt core:setup-repo in a Python repo #5.
Piloting in retina-tracker (#5, a PUBLIC repo), automated security review flagged HIGH on the workflow assets:
claude.yml's@claudetrigger is invokable by ANY commenter, now write-scoped — needs anauthor_association(OWNER/MEMBER/COLLABORATOR) guard on theif:gate. Applied in retina-tracker; propose a public-repo template variant.pull-requests: writeon the review workflow'spull_requesttrigger is fork-exploitable on public repos; documentpull_request_target+ author allow-list guidance.astral-sh/setup-uv@v5,anthropics/claude-code-action@v1); add top-levelpermissions: { contents: read }to ci.yml.Refs Pilot: adopt core:setup-repo in a Python repo #5.