Skip to content

Adding gitspiegel-trigger workflow#2661

Merged
mutantcornholio merged 1 commit intomasterfrom
yuri/gitspiegel-trigger
Oct 30, 2023
Merged

Adding gitspiegel-trigger workflow#2661
mutantcornholio merged 1 commit intomasterfrom
yuri/gitspiegel-trigger

Conversation

@mutantcornholio
Copy link
Copy Markdown
Contributor

Using a workflow to trigger mirroring instead of a webhook allows us to reuse "Approving workflow runs from public forks" GitHub feature to somewhat protect us from malicious PRs

Using a workflow to trigger mirroring instead of a webhook allows us to reuse "Approving workflow runs from public forks" GitHub feature to somewhat protect us from malicious PRs
@mutantcornholio mutantcornholio requested a review from a team as a code owner October 30, 2023 10:32
@mutantcornholio mutantcornholio merged commit 75df0eb into master Oct 30, 2023
@mutantcornholio mutantcornholio deleted the yuri/gitspiegel-trigger branch October 30, 2023 10:49
svyatonik pushed a commit that referenced this pull request Nov 14, 2023
Using a workflow to trigger mirroring instead of a webhook allows us to reuse "Approving workflow runs from public forks" GitHub feature to somewhat protect us from malicious PRs
svyatonik pushed a commit that referenced this pull request Nov 14, 2023
Using a workflow to trigger mirroring instead of a webhook allows us to reuse "Approving workflow runs from public forks" GitHub feature to somewhat protect us from malicious PRs
svyatonik added a commit that referenced this pull request Nov 14, 2023
* Adding gitspiegel-trigger workflow (#2661)

Using a workflow to trigger mirroring instead of a webhook allows us to reuse "Approving workflow runs from public forks" GitHub feature to somewhat protect us from malicious PRs

* Fixing gitspiegel trigger workflow (#2679)

The first attept to use a workflow to protect GitLab CI from untrusted contributors failed, because GitHub doesn't pass secrets to workflows for PRs that originate from forks. 
 
This uses a different approach: instead of triggerring gitspiegel API directly from the workflow, we're just spawning an empty workflow with a specific path, and gitspiegel listens for `workflow_run` event to start mirroring.  

The idea is the same: for the first-time contributors, running workflows would require manual aciton and that would block mirroring. But this time, we don't need any secrets to make it work.

---------

Co-authored-by: Yuri Volkov <0@mcornholio.ru>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants