fix(ci): require an org member to trigger Claude and keep self-hosted jobs off pull requests - #587
Draft
jacobwgillespie wants to merge 1 commit into
Conversation
Co-authored-by: Jacob Gillespie <jacobwgillespie@gmail.com>
|
This pull request is waiting on a decision: merge it if the change is still wanted, or close it if the fix is no longer needed. Either one settles it. It was opened on 2026-09-21 and has had no new activity for a week. If nothing happens on it within a week, Polylane closes it and keeps the branch, so reopening it brings the change back exactly as it stands. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Public interactions could schedule work on the shared self-hosted fleet from outside Depot, both through assistant requests and pull requests. That exposed infrastructure used for CI and production delivery to untrusted workloads and could make repository credentials available to an outside-triggered assistant job. Merging this change limits assistant requests to trusted contributors and keeps pull-request work off that fleet.
Before / After
Before: Anyone able to comment, review, or open an issue could request the assistant, causing an outside-authored request to consume Depot-hosted compute and act with repository-provided credentials. Pull requests also scheduled lint, build, or test work on the same shared fleet: fork pull requests selected lint and build, while every pull request selected tests, duplicating test work for same-repository branches.
After: Assistant requests from owners, organization members, and repository collaborators continue to run as before, while requests from all other associations end without allocating a runner or exposing credentials. Pull-request events skip every self-hosted CI job. Branch pushes remain the source of lint, build, and test coverage, so trusted same-repository development keeps one copy of those checks without pull-request duplication.
Changes
OWNER,MEMBER, orCOLLABORATORassociation on every supported Claude event before honoring@claude.pull_requestevents.Validation
actionlint -oneline .github/workflows/claude.yml .github/workflows/ci.ymlβ no new findings and none on the changed conditions. Output remains the same eight pre-existing findings: four unknown self-hosted runner labels, three deprecatedset-outputcommands, and one boolean property-access warning.OWNER,MEMBER, andCOLLABORATOR; rejectedNONEandFIRST_TIME_CONTRIBUTOR; acceptedpush; rejected same-repository and forkpull_requestevents.make testβ passed.go mod verify && go mod downloadβ passed.go fmt ./... && git diff --exit-code && go mod tidy -diffβ passed with no changes.golangci-lint v2.4.0 run --timeout 5mβ passed with 0 issues.pnpm install --frozen-lockfile --ignore-scriptsβ passed using pnpm 11.22.0.pnpm fmt:checkβ passed.pnpm type-checkβ passed.Workflow evidence
pull_requestrun 35606359012:lint,build, andtestwere skipped; each has no runner name or runner group.pushrun 35606311958:lint,build, andtestsucceeded ondepot-*runners in runner groupdefault.Assumptions and remaining controls
pushremains enabled for all branches, so same-repository branches retain lint, build, and test coverage after the pull-request jobs are skipped. A fork can still modify its copy of a workflow before apull_requestevent; repository or organization fork-approval policy and runner-group isolation remain required to close that path independently. The wildcard OIDC trust policy is also outside this change.Fixes: Public repos run untrusted-trigger jobs on Depot's shared self-hosted runner fleet (fork PRs and any-commenter events, no guard)
What caused this
Affected:
int_03fe8cc8c001b4k2ztpwmo0uA check caught it, an investigation traced it, an autofix wrote the change. Each step links to its record.
fix_0c4284β¦This pull request originated from a Polylane autofix. Polylane investigated the issue and delegated the fix to Cursor, which authored this pull request.