Skip to content

ci(e2e): only run the self-hosted e2e job for htilly - #347

Open
htilly wants to merge 1 commit into
masterfrom
chore/e2e-actor-guard
Open

htilly wants to merge 1 commit into
masterfrom
chore/e2e-actor-guard

Conversation

@htilly

@htilly htilly commented Sep 26, 2026

Copy link
Copy Markdown
Owner

Adds if: github.actor == 'htilly' to the e2e job, plus a comment explaining why.

Why: the e2e job targets a self-hosted runner on a host that has LAN access and live Slack/Spotify/OpenAI credentials on disk, and this repository is public (38 forks, 136 stars).

Scope of the guard — please read: this is a backstop, not the primary control. For pull_request events GitHub uses the workflow files from the PR head, so a PR can simply delete this if:. The control that actually gates untrusted code is the repository setting Settings → Actions → Fork pull request workflows from outside collaborators → Require approval for all external contributors, which was changed from first_time_contributors to all_external_contributors alongside this PR.

record-history is deliberately left unguarded: it runs on ubuntu-latest, not the self-hosted runner.

Not merged — for your review.

The e2e job runs on a self-hosted runner on a host with LAN access and
live Slack/Spotify credentials on disk, in a public repository. Guard the
job on github.actor so it cannot run for anyone else.

This is a backstop, not the primary control: a pull request can edit this
file, so the repository's fork-PR approval setting is what actually gates
untrusted code. Both together.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant