Skip to content
This repository was archived by the owner on Jan 21, 2025. It is now read-only.

Fixing gitspiegel trigger workflow#251

Merged
mutantcornholio merged 1 commit intomasterfrom
yuri/gitspiegel-trigger-fix
Nov 8, 2023
Merged

Fixing gitspiegel trigger workflow#251
mutantcornholio merged 1 commit intomasterfrom
yuri/gitspiegel-trigger-fix

Conversation

@mutantcornholio
Copy link
Contributor

The first attept to use a workflow to protect GitLab CI from untrusted contributors failed, because GitHub doesn't pass secrets to workflows for PRs that originate from forks.

This uses a different approach: instead of triggerring gitspiegel API directly from the workflow, we're just spawning an empty workflow with a specific path, and gitspiegel listens for workflow_run event to start mirroring.

The idea is the same: for the first-time contributors, running workflows would require manual aciton and that would block mirroring. But this time, we don't need any secrets to make it work.

The first attept to use a workflow to protect GitLab CI from untrusted contributors failed, because GitHub doesn't pass secrets to workflows for PRs that originate from forks. 
 
This uses a different approach: instead of triggerring gitspiegel API directly from the workflow, we're just spawning an empty workflow with a specific path, and gitspiegel listens for `workflow_run` event to start mirroring.  

The idea is the same: for the first-time contributors, running workflows would require manual aciton and that would block mirroring. But this time, we don't need any secrets to make it work.

Signed-off-by: Yuri Volkov <0@mcornholio.ru>
@mutantcornholio mutantcornholio requested a review from a team as a code owner November 8, 2023 12:21
@mutantcornholio mutantcornholio merged commit e993dd1 into master Nov 8, 2023
@mutantcornholio mutantcornholio deleted the yuri/gitspiegel-trigger-fix branch November 8, 2023 13:19
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants