skip running unsafe pr check if input is default (#2518)

This commit is contained in:
Aiqiao Yan authored and GitHub committed 2026-07-15 10:02:03 -04:00
1 parent e8d4307400
commit 62661c4e71
3 files changed
+72 -12

No files matched your search

+13 -6
View File
@@ -42191,12 +42191,19 @@ async function getInputs() {
(getInput('allow-unsafe-pr-checkout') || 'false').toUpperCase() ===
'TRUE';
core_debug(`allow unsafe PR checkout = ${result.allowUnsafePrCheckout}`);
assertSafePrCheckout({
qualifiedRepository,
ref: result.ref,
commit: result.commit,
allowUnsafePrCheckout: result.allowUnsafePrCheckout
});
// The default self-checkout (this repository with no explicit ref) always
// resolves to the trusted ref/commit GitHub set for the triggering event, so
// the fork-checkout guard only needs to run when the caller customized the
// repository or ref.
const isDefaultCheckout = isWorkflowRepository && !getInput('ref');
if (!isDefaultCheckout) {
assertSafePrCheckout({
qualifiedRepository,
ref: result.ref,
commit: result.commit,
allowUnsafePrCheckout: result.allowUnsafePrCheckout
});
}
return result;
}