Skip to content

fix(ci): require an org member to trigger Claude and keep self-hosted jobs off pull requests - #587

Draft
jacobwgillespie wants to merge 1 commit into
mainfrom
cursor/polylane-autofix-fix-ci-require-an-org-member-to-trigger-claude-and-keep-self-hosted-jobs-off-pu-b224
Draft

jacobwgillespie wants to merge 1 commit into
mainfrom
cursor/polylane-autofix-fix-ci-require-an-org-member-to-trigger-claude-and-keep-self-hosted-jobs-off-pu-b224

Conversation

@jacobwgillespie

@jacobwgillespie jacobwgillespie commented Sep 21, 2026 •

Copy link
Copy Markdown
Member

Public interactions could schedule work on the shared self-hosted fleet from outside Depot, both through assistant requests and pull requests. That exposed infrastructure used for CI and production delivery to untrusted workloads and could make repository credentials available to an outside-triggered assistant job. Merging this change limits assistant requests to trusted contributors and keeps pull-request work off that fleet.

Before / After

Before: Anyone able to comment, review, or open an issue could request the assistant, causing an outside-authored request to consume Depot-hosted compute and act with repository-provided credentials. Pull requests also scheduled lint, build, or test work on the same shared fleet: fork pull requests selected lint and build, while every pull request selected tests, duplicating test work for same-repository branches.

After: Assistant requests from owners, organization members, and repository collaborators continue to run as before, while requests from all other associations end without allocating a runner or exposing credentials. Pull-request events skip every self-hosted CI job. Branch pushes remain the source of lint, build, and test coverage, so trusted same-repository development keeps one copy of those checks without pull-request duplication.

Changes

  • Require OWNER, MEMBER, or COLLABORATOR association on every supported Claude event before honoring @claude.
  • Run the self-hosted lint, build, and test jobs only for non-pull_request events.
  • Leave the GitHub-hosted package job, runner labels, and Claude permissions unchanged.

Validation

  • actionlint -oneline .github/workflows/claude.yml .github/workflows/ci.yml β€” no new findings and none on the changed conditions. Output remains the same eight pre-existing findings: four unknown self-hosted runner labels, three deprecated set-output commands, and one boolean property-access warning.
  • Stdlib guard replay β€” accepted OWNER, MEMBER, and COLLABORATOR; rejected NONE and FIRST_TIME_CONTRIBUTOR; accepted push; rejected same-repository and fork pull_request events.
  • make test β€” passed.
  • go mod verify && go mod download β€” passed.
  • go fmt ./... && git diff --exit-code && go mod tidy -diff β€” passed with no changes.
  • golangci-lint v2.4.0 run --timeout 5m β€” passed with 0 issues.
  • pnpm install --frozen-lockfile --ignore-scripts β€” passed using pnpm 11.22.0.
  • pnpm fmt:check β€” passed.
  • pnpm type-check β€” passed.

Workflow evidence

Assumptions and remaining controls

push remains enabled for all branches, so same-repository branches retain lint, build, and test coverage after the pull-request jobs are skipped. A fork can still modify its copy of a workflow before a pull_request event; repository or organization fork-approval policy and runner-group isolation remain required to close that path independently. The wildcard OIDC trust policy is also outside this change.

Open in WebΒ Open in CursorΒ 

Fixes: Public repos run untrusted-trigger jobs on Depot's shared self-hosted runner fleet (fork PRs and any-commenter events, no guard)

What caused this

Affected: int_03fe8cc8c001b4k2ztpwmo0u

A check caught it, an investigation traced it, an autofix wrote the change. Each step links to its record.

Step Where to look
1. An issue from an exploration was opened Open the investigation
2. A fix run traced the cause Fix run thread
3. An autofix wrote the change, and it succeeded Autofix fix_0c4284…
4. This pull request opened it for review this PR

View thread

This pull request originated from a Polylane autofix. Polylane investigated the issue and delegated the fix to Cursor, which authored this pull request.

Co-authored-by: Jacob Gillespie <jacobwgillespie@gmail.com>
@polylane polylane Bot added the polylane label Sep 21, 2026
@polylane

polylane Bot commented Sep 30, 2026

Copy link
Copy Markdown

This pull request is waiting on a decision: merge it if the change is still wanted, or close it if the fix is no longer needed. Either one settles it.

It was opened on 2026-09-21 and has had no new activity for a week. If nothing happens on it within a week, Polylane closes it and keeps the branch, so reopening it brings the change back exactly as it stands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants