From 6f0a2af42dbe327652c85ce6586c8a0838b03459 Mon Sep 17 00:00:00 2001 From: SpencerJung Date: Wed, 27 May 2026 12:50:30 +0900 Subject: [PATCH] security(ci): gate self-hosted jobs to base-repo PRs only Add explicit fork-PR guards to all self-hosted (WarpBuild) jobs in ci.yml so that pull requests from forked repositories cannot trigger arbitrary code execution on the project's build machines. The guard skips the job when the PR head repository differs from the base repository. Fixes #385. --- .github/workflows/ci.yml | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index bc26d9a970e3..c59d34bbf3d5 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -156,6 +156,7 @@ jobs: tests: runs-on: warp-macos-15-arm64-6x + if: github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository timeout-minutes: 75 env: CMUX_SKIP_ZIG_BUILD: "1" @@ -387,6 +388,7 @@ jobs: # and performance regressions stay isolated. Broader interactive UI suites # still run via test-e2e.yml on GitHub-hosted runners. runs-on: warp-macos-15-arm64-6x + if: github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository timeout-minutes: 20 steps: - name: Checkout @@ -573,6 +575,7 @@ jobs: # signing, notarization, and publishing. This catches DEBUG/Release boundary # mistakes before they reach main. runs-on: warp-macos-26-arm64-6x + if: github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository timeout-minutes: 20 steps: - name: Checkout @@ -656,6 +659,7 @@ jobs: ui-regressions: runs-on: warp-macos-15-arm64-6x + if: github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository timeout-minutes: 25 steps: - name: Checkout