Skip to content

Fixing gitspiegel trigger workflow#115

Merged
PierreBesson merged 1 commit intomainfrom
yuri/gitspiegel-trigger-fix
Nov 7, 2023
Merged

Fixing gitspiegel trigger workflow#115
PierreBesson merged 1 commit intomainfrom
yuri/gitspiegel-trigger-fix

Conversation

@mutantcornholio
Copy link
Copy Markdown
Contributor

The first attept to use a workflow to protect GitLab CI from untrusted contributors failed, because GitHub doesn't pass secrets to workflows for PRs that originate from forks.

This uses a different approach: instead of triggerring gitspiegel API directly from the workflow, we're just spawning an empty workflow with a specific path, and gitspiegel listens for workflow_run event to start mirroring.

The idea is the same: for the first-time contributors, running workflows would require manual aciton and that would block mirroring. But this time, we don't need any secrets to make it work.

The first attept to use a workflow to protect GitLab CI from untrusted contributors failed, because GitHub doesn't pass secrets to workflows for PRs that originate from forks. 
 
This uses a different approach: instead of triggerring gitspiegel API directly from the workflow, we're just spawning an empty workflow with a specific path, and gitspiegel listens for `workflow_run` event to start mirroring.  

The idea is the same: for the first-time contributors, running workflows would require manual aciton and that would block mirroring. But this time, we don't need any secrets to make it work.
@PierreBesson PierreBesson merged commit 22abbb6 into main Nov 7, 2023
@PierreBesson PierreBesson deleted the yuri/gitspiegel-trigger-fix branch November 7, 2023 17:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants