Replies: 7 comments 1 reply
-
This is a significant pain point for Keycloak and limits the usefulness of the GitHub Security Advisory product overall. |
Beta Was this translation helpful? Give feedback.
-
This same problem came up for me in a separate, partially-related discussion: |
Beta Was this translation helpful? Give feedback.
-
This limitation is also very problematic for the Quarkus project. It makes this feature close to unusable as we really need to make sure the tests are passing before merging and running them locally is not really an option. |
Beta Was this translation helpful? Give feedback.
-
Here's this feature request on the GitHub product roadmap: github/roadmap#627 |
Beta Was this translation helpful? Give feedback.
-
Here's what I just posted in the Security Advisories Feature Requests & Improvements thread. https://github.com/orgs/community/discussions/12226#discussioncomment-8458224 |
Beta Was this translation helpful? Give feedback.
-
Adding my voice, we have been frustrated by this lack for a long time. We need CI in temporary private repositories. There are security concerns when adding it, but the current situation is also a security problem: The release process constantly risks being disrupted by problems CI would have discovered. So we risk security fixes being made public quite some time before the fix is actually usable, granting more time for bad actors to exploit before fixes are installed. |
Beta Was this translation helpful? Give feedback.
-
This comment is here so I will get notification about this thread. |
Beta Was this translation helpful? Give feedback.
-
Is there a way to run GitHub Actions against a temporary private fork created from a Security Advisory?
As far as I can see, there's no Actions tab on the private fork and I couldn't find anything relevant by googling around (maybe my searches were bad 🤷).
The only recent information I could find is on this blog post:
They suggest using nektos/act for running the GitHub Actions locally, but this doesn't fit our use case.
Would it be possible to run GHA with Self-hosted runners maybe?
Beta Was this translation helpful? Give feedback.
All reactions