failed attributes
| status |
attribute |
duration |
| failed |
aarch64-darwin.treefmt
|
6s |
> +always read from the **default branch's** `buildbot-nix.toml` (via `git
> +show`)
> +so that pull request authors cannot grant themselves effects access.
> + …
> +always read from the **default branch's** `buildbot-nix.toml` (via `git
> +show`)
> +so that pull request authors cannot grant themselves effects access.
> +
> +:::{caution} PR effects receive the same `effects_per_repo_secrets` as
> +default-branch effects. A malicious PR can modify the effect code to exfiltrate
> +these secrets. Only enable {confval}`effects_on_pull_requests` for repositories
> +where you trust all contributors, or where no secrets are configured. :::
Reason: builder failed with exit code 1.
|
| failed |
aarch64-linux.treefmt
|
17s |
> +always read from the **default branch's** `buildbot-nix.toml` (via `git
> +show`)
> +so that pull request authors cannot grant themselves effects access.
> + …
> +always read from the **default branch's** `buildbot-nix.toml` (via `git
> +show`)
> +so that pull request authors cannot grant themselves effects access.
> +
> +:::{caution} PR effects receive the same `effects_per_repo_secrets` as
> +default-branch effects. A malicious PR can modify the effect code to exfiltrate
> +these secrets. Only enable {confval}`effects_on_pull_requests` for repositories
> +where you trust all contributors, or where no secrets are configured. :::
Reason: builder failed with exit code 1.
|
| failed |
x86_64-linux.treefmt
|
13s |
> +always read from the **default branch's** `buildbot-nix.toml` (via `git
> +show`)
> +so that pull request authors cannot grant themselves effects access.
> + …
> +always read from the **default branch's** `buildbot-nix.toml` (via `git
> +show`)
> +so that pull request authors cannot grant themselves effects access.
> +
> +:::{caution} PR effects receive the same `effects_per_repo_secrets` as
> +default-branch effects. A malicious PR can modify the effect code to exfiltrate
> +these secrets. Only enable {confval}`effects_on_pull_requests` for repositories
> +where you trust all contributors, or where no secrets are configured. :::
|