Details
-
New Feature
-
Status: Reopened (View Workflow)
-
Major
-
Resolution: Unresolved
Description
The plugin currently has no way to block untrusted users from making a PR from a fork and having this PR built by Jenkins. The GitHub Pull Request Builder does have this feature which is very useful for open source projects to protect the build system from malicious changes. The documentation on the GitHub Pull Request Builder wiki page says to move from the GHPRB plugin to the GitHub Branch source plugin which causes the user to lose this extremely useful functionality.
Attachments
Issue Links
- is duplicated by
-
JENKINS-55778 Github branch source plugin builds untrusted builds during scan
-
- Resolved
-
- relates to
-
JENKINS-46795 Abort builds with untrusted Jenkinsfile, but only given passive cause
-
- In Review
-
-
JENKINS-53753 Misleading documentation for permissions
-
- Open
-
- links to
Activity
Field | Original Value | New Value |
---|---|---|
Attachment | github-branch-source-discover-pull-requests.PNG [ 44586 ] |
Link | This issue relates to JENKINS-53753 [ JENKINS-53753 ] |
Assignee | Andrew Bayer [ abayer ] |
Status | Open [ 1 ] | In Progress [ 3 ] |
Status | In Progress [ 3 ] | In Review [ 10005 ] |
Remote Link | This issue links to "PR #188 (Web Link)" [ 21838 ] |
Assignee | Andrew Bayer [ abayer ] | rsandell [ rsandell ] |
Remote Link | This issue links to "scm-api#56 (Web Link)" [ 22168 ] |
Link |
This issue is duplicated by |
Assignee | rsandell [ rsandell ] | Liam Newman [ bitwiseman ] |
Attachment | image-2019-07-23-10-28-00-893.png [ 48060 ] |
Resolution | Fixed [ 1 ] | |
Status | In Review [ 10005 ] | Resolved [ 5 ] |
Resolution | Fixed [ 1 ] | |
Status | Resolved [ 5 ] | Reopened [ 4 ] |
Labels | configuration security | configuration security stalled-pr |
Assignee | Liam Newman [ bitwiseman ] |
Link | This issue relates to JENKINS-46795 [ JENKINS-46795 ] |