Dependabotã®ä½ã£ãPRãSecretsã«ã¢ã¯ã»ã¹ã§ããªãããã«ãã¨ãã¨ã失æãã¦ããã®ãä¿®æ£ãã¾ããã github.com Secretsã«ã¢ã¯ã»ã¹ã§ããªãã®ã¯Keeping your GitHub Actions and workflows secure: Preventing pwn requestsã§èª¬æããã¦ããããã«ã»ãã¥ãªãã£åä¸ã®ããã§ããworkflow_run ã¤ãã³ãã§Checkãåãã¨ã¯ã¼ã¯ããã¼å®ç¾©ã¯å¸¸ã«ããã©ã«ããã©ã³ãã®ãã®ã使ããããããPRã§ã¯ã¼ã¯ããã¼ãã¡ã¤ã«ãæªæãæã£ã¦å¤æ´ããã¦ããã¼ã¸ããªããã°æªå½±é¿ãåãã¾ãããã®ã§ä»å¾ãåºæ¬çã«ã¯Secretsãå¿ è¦ã¨ããã¯ã¼ã¯ããã¼ã¯workflow_runã¤ãã³ãã§åããã¨ã«ãªãã¾ãã ä¸è¨securitylab.github.comã®è¨äºã§è²ã 説æããã¦ãã¾ãããããã¨éå®çãªã¦ã¼ã¹ã±ã¼ã¹ã«ã¤ã


{{#tags}}- {{label}}
{{/tags}}