Skip to content

Commit c4767cd

Browse files
authored
ci: changed pull_request_target to pull_request and removed the authorize step (#416)
1 parent b2ec8a8 commit c4767cd

File tree

2 files changed

+2
-16
lines changed

2 files changed

+2
-16
lines changed

.github/workflows/semgrep.yml

+1-8
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@ name: Semgrep
22

33
on:
44
merge_group:
5-
pull_request_target:
5+
pull_request:
66
types:
77
- opened
88
- synchronize
@@ -20,15 +20,8 @@ concurrency:
2020
cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
2121

2222
jobs:
23-
authorize:
24-
name: Authorize
25-
environment: ${{ github.actor != 'dependabot[bot]' && github.event_name == 'pull_request_target' && github.event.pull_request.head.repo.full_name != github.repository && 'external' || 'internal' }}
26-
runs-on: ubuntu-latest
27-
steps:
28-
- run: true
2923

3024
run:
31-
needs: authorize # Require approval before running on forked pull requests
3225

3326
name: Check for Vulnerabilities
3427
runs-on: ubuntu-latest

.github/workflows/snyk.yml

+1-8
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@ name: Snyk
33
on:
44
merge_group:
55
workflow_dispatch:
6-
pull_request_target:
6+
pull_request:
77
types:
88
- opened
99
- synchronize
@@ -21,15 +21,8 @@ concurrency:
2121
cancel-in-progress: ${{ github.ref != 'refs/heads/master' }}
2222

2323
jobs:
24-
authorize:
25-
name: Authorize
26-
environment: ${{ github.actor != 'dependabot[bot]' && github.event_name == 'pull_request_target' && github.event.pull_request.head.repo.full_name != github.repository && 'external' || 'internal' }}
27-
runs-on: ubuntu-latest
28-
steps:
29-
- run: true
3024

3125
check:
32-
needs: authorize
3326

3427
name: Check for Vulnerabilities
3528
runs-on: ubuntu-latest

0 commit comments

Comments
 (0)