Conversation
|
/fix-all |
|
🤖 Command |
|
❌ Command |
|
oh ok |
|
See example: #8081 (comment) |
a47f476 to
dc1623d
Compare
|
/fix-all |
|
🤖 Command |
|
✅ Command |
6fb676e to
f84a69b
Compare
|
/fix-all |
|
🤖 Command |
|
✅ Command |
0669777 to
9ce9b1a
Compare
|
/fix-all |
|
🤖 Command |
|
❌ Command |
|
/fix-all |
|
🤖 Command |
|
❌ Command |
|
Sorry for the spam |
|
No worries, seems to work fine? |
|
/fix-all |
|
🤖 Command |
|
❌ Command |
a33b282 to
0b1ceae
Compare
|
/fix-all |
|
🤖 Command |
|
✅ Command |
|
@Alkarex I don't have permissions to change labels but I was able to do that using the action. Seems like a vulnerability? |
|
relevant zizmor output: |
0b1ceae to
6cea564
Compare
|
/fix-all |
|
🤖 Command |
|
✅ Command |
|
I can also change title of #8093 to "pwn" I think it's also possible to add commits to PRs but I already had trouble doing that (look at the spam before) |
|
Oh wait the action also has I would try to do that but I don't know git very well[1], so best to fix this as soon as possible [1]: this line is making it hard, it wasn't there before: FreshRSS/.github/workflows/commands.yml Line 64 in 458832c |
|
Good catch. PR welcome if you can |
|
Note that whatever malicious commit would get added to latest/edge, it also gets published to Docker automatically...
|
|
I have temporarily disabled it, until it is fixed |
|
/fix-all (it's disabled) |
ignore this PR