Skip to content

Commit e89a83a

Browse files
committed
Check who opened the pull request before auto-merging it
The Dependabot auto-merge job ran when github.actor was dependabot[bot]. zizmor (bot-conditions) flags that as spoofable: the actor is whoever caused the event, so a run Dependabot triggers on a pull request someone else opened passes the check, and the job then approves the pull request and enables auto-merge. The job now checks github.event.pull_request.user.login, the author of the pull request, which is the condition GitHub's own documentation for Dependabot auto-merge uses. dependabot/fetch-metadata still checks the author and that the commits are Dependabot's before anything is approved.
1 parent a5b690e commit e89a83a

1 file changed

Lines changed: 3 additions & 1 deletion

File tree

‎.github/workflows/dependabot-automerge.yml‎

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,9 @@ permissions:
99
jobs:
1010
dependabot:
1111
runs-on: ubuntu-latest
12-
if: github.actor == 'dependabot[bot]'
12+
# Who opened the pull request, not who triggered this run: github.actor is whoever caused the event,
13+
# and a run that Dependabot triggers on someone else's pull request would pass an actor check.
14+
if: github.event.pull_request.user.login == 'dependabot[bot]'
1315
steps:
1416
- name: Fetch Dependabot metadata
1517
id: metadata

0 commit comments

Comments
 (0)