Skip to content

ci: run verify on GitHub-hosted ubuntu - #2

Merged
lnittman merged 1 commit into
mainfrom
ci/github-hosted-verify-20260927
Sep 27, 2026
Merged

lnittman merged 1 commit into
mainfrom
ci/github-hosted-verify-20260927

Conversation

@lnittman

Copy link
Copy Markdown
Contributor

This public repo ran verify on the org's shared self-hosted pool (nit). Jobs there could read the host user's credentials, and fork PRs needed approval only from first-time contributors. Finding: agents/nit-runner-pool-plaintext-github-token-shared-by-all-repos-20260927.

GitHub-hosted runners are free for public repos. This job is plain Node/pnpm, and I checked the repo before switching: no macOS-only commands, no private @creative-int packages.

  • runs-on: ubuntu-latest
  • permissions: contents: read

After this merges, the org's Default runner group stops accepting public repos.

🤖 Generated with Claude Code

This public repo ran its verify job on the org's shared self-hosted pool on
nit. That pool's runners could read the host user's credentials, and fork
PRs from first-time contributors are the only ones needing approval.
GitHub-hosted runners are free for public repos, and this job is plain
Node/pnpm with no macOS-only steps and no private packages.

Also scopes the job's GITHUB_TOKEN to contents: read.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@lnittman
lnittman merged commit 2151b42 into main Sep 27, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant