Skip to content

ci: Fix CodeQL warnings for renovate-semconv#2174

Merged
kaylareopelle merged 1 commit into
open-telemetry:mainfrom
kaylareopelle:fix-renovate-semconv-codeql-warnings
Jun 9, 2026
Merged

ci: Fix CodeQL warnings for renovate-semconv#2174
kaylareopelle merged 1 commit into
open-telemetry:mainfrom
kaylareopelle:fix-renovate-semconv-codeql-warnings

Conversation

@kaylareopelle

Copy link
Copy Markdown
Contributor

Two concerns:

  1. pull_request_target can be run with write permissions on forks and access to secrets. Since all branches referenced are in the same repo, we can just use pull_request
  2. Script injection could hijack github.base_ref to do bad things

Fixes failures on #2169

Two concerns:
1. pull_request_target can be run with
write permissions on forks and access to secrets. Since all branches
referenced are in the same repo, we can just use pull_request
2. Script injection could hijack github.base_ref to do bad things
@kaylareopelle kaylareopelle merged commit 3ee61cd into open-telemetry:main Jun 9, 2026
63 checks passed
@kaylareopelle kaylareopelle deleted the fix-renovate-semconv-codeql-warnings branch June 9, 2026 16:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants