Skip to content

ci: protect self-hosted runners from fork PRs#1370

Merged
kunxian-xia merged 1 commit into
masterfrom
fix/self-hosted-pr-ci
Jun 24, 2026
Merged

ci: protect self-hosted runners from fork PRs#1370
kunxian-xia merged 1 commit into
masterfrom
fix/self-hosted-pr-ci

Conversation

@kunxian-xia

@kunxian-xia kunxian-xia commented Jun 23, 2026

Copy link
Copy Markdown
Collaborator

Summary

We want to thank Sujal Tuladhar (EvilGenius) for reporting this vulnerability.

  • skip self-hosted integration jobs for fork PRs
  • require same-repo PRs for GPU self-hosted CI and isolate PR cargo target output
  • unset the runner registration PAT before starting the Actions runner
  • document fork PR, PAT, and cache isolation guidance for the GPU runner

@kunxian-xia kunxian-xia added this pull request to the merge queue Jun 24, 2026
Merged via the queue into master with commit 3df3d09 Jun 24, 2026
6 checks passed
@kunxian-xia kunxian-xia deleted the fix/self-hosted-pr-ci branch June 24, 2026 03:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants