Skip to content

Allow Pushing to Fork #267

@squat

Description

@squat

peter-evans/create-pull-request has an input named push-to-fork which allows pushing PR branches to a fork and creating the PR to the parent repository from the fork. This allows following the

principle of least privilege by using a dedicated user acting as a machine account ... [that] ... only has read access to the main repository.

In light of all of the recent supply-chain hacks, I think enabling pushing PR branches to forks is a good feature for update-flack-lock so that repo-owners can lock down their repos and prevent issuing PATs to their bot accounts with write permissions on the main repository.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions