From 843b2e5d331f099ae7e6d7f75bdf0806ac267be7 Mon Sep 17 00:00:00 2001 From: Ramon Petgrave Date: Tue, 23 Apr 2024 20:36:03 +0000 Subject: [PATCH] more docs Signed-off-by: Ramon Petgrave --- .github/workflows/post-commit.yml | 3 +++ 1 file changed, 3 insertions(+) diff --git a/.github/workflows/post-commit.yml b/.github/workflows/post-commit.yml index f05ced4..cc4c15b 100644 --- a/.github/workflows/post-commit.yml +++ b/.github/workflows/post-commit.yml @@ -1,5 +1,8 @@ # A workflow to run against renovate-bot's PRs, # such as `make package` after it updates the package.json and package-lock.json files. +# The potentially untrusted code is first run inside a low-privilege Job, and the diff is uploaded as an artifact. +# Then a higher-privilage Job applies the diff and pushes the changes to the PR. +# It's important to only run this workflow against PRs from trusted sources, after also reviewing the changes! name: Post-Commit