Conversation
|
|
Signed-off-by: Charlie Doern <cdoern@redhat.com>
|
This seems wrong since the change doesn't get rid of secrets read in e2e step. Unless we can fetch models and such without tokens, we cannot have the job as pull_request_target. |
|
I am still working on this, comparing it to the one in instructlab/instructlab. In the meantime we can consider disabling this workflow on PRs if there is one we need to merge. |
|
This pull request has been automatically marked as stale because it has not had activity within 90 days. It will be automatically closed if no further activity occurs within 30 days. |
|
This pull request has merge conflicts that must be resolved before it can be |
|
This pull request has been automatically marked as stale because it has not had activity within 90 days. It will be automatically closed if no further activity occurs within 30 days. |
|
This pull request has been automatically closed due to inactivity. Please feel free to reopen if you intend to continue working on it! |
the medium e2e job should:
pull_request_targetproperly to gate access to secrets from untested code