Repository navigation
feat: AdMob 광고 실험 추가 (#87) #88
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from 2 commits
Commits
Show all changes
3 commits
Select commit
Hold shift + click to select a range
File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,20 @@ | ||
| name: Request CodeRabbit review | ||
|
|
||
| on: | ||
| pull_request: | ||
| branches: [develop] | ||
| types: [ready_for_review] | ||
|
|
||
| permissions: | ||
| issues: write | ||
| pull-requests: write | ||
|
|
||
| jobs: | ||
| request-review: | ||
| runs-on: ubuntu-latest | ||
| steps: | ||
| - name: Request full review | ||
| run: gh pr comment "$PR_URL" --body '@coderabbitai full review' | ||
| env: | ||
| GH_TOKEN: ${{ github.token }} | ||
| PR_URL: ${{ github.event.pull_request.html_url }} | ||
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🔒 Security & Privacy | 🛡️ Analyzed with Security Review | 🟠 Major | ⚡ Quick win
🧩 Analysis chain
🌐 Web query:
site:docs.github.com rest issues comments create an issue comment fine-grained access tokens Issues write Pull requests write💡 Result:
<search_synthesis>
To create an issue comment using the GitHub REST API (POST /repos/{owner}/{repo}/issues/{issue_number}/comments) with a fine-grained personal access token, you must grant the token the Issues permission with write access [1][2]. While GitHub treats every pull request as an issue [3], the fine-grained permission model distinguishes between them for specific operations [1]. Specifically: - To comment on an issue, the Issues: write permission is required [1][2]. - To comment on a pull request, you generally require the Pull requests: write permission [1][2]. If you encounter a 403 error or a "Resource not accessible by personal access token" message, you should check the X-Accepted-GitHub-Permissions header returned in the API response [4][5]. This header explicitly lists the required permissions for the endpoint you are calling [5]. You can manage and update the permissions for your fine-grained token in your GitHub account settings under Personal access tokens [1].
</search_synthesis>
<source_evidence>
Citations:
🌐 Web query:
site:docs.github.com site:cli.github.com gh pr comment exact REST endpoint POST /repos/{owner}/{repo}/issues/{issue_number}/comments issues write pull-requests write GITHUB_TOKEN💡 Result:
<search_synthesis>
To create a comment on an issue or pull request using the GitHub REST API, use the POST /repos/{owner}/{repo}/issues/{issue_number}/comments endpoint [1][2][3]. Permissions and Scopes To access this endpoint, your token (such as a GITHUB_TOKEN in GitHub Actions, a fine-grained personal access token, or a GitHub App token) must have write access to either the "Issues" or "Pull requests" repository permissions [3]. Implementation Details 1. Endpoint: POST /repos/{owner}/{repo}/issues/{issue_number}/comments [1][4]. 2. Required Body Parameter: body (string) containing the comment text [1][3]. 3. GitHub Actions (GITHUB_TOKEN): If you are using this in a GitHub Actions workflow, you must explicitly grant the necessary permissions in your workflow configuration file [5]. Example YAML configuration for permissions: permissions: issues: write pull-requests: write Note: Because a pull request is technically an issue in the GitHub API, you use the same issue comment endpoint to add standard comments to the timeline of a pull request [6][3]. If you intend to create a review comment on a specific line of code in a pull request diff, you should instead use the POST /repos/{owner}/{repo}/pulls/{pull_number}/comments endpoint [7][8].
</search_synthesis>
<source_evidence>
Citations:
Security Misconfiguration
Reachability: External
Exploitability: Difficult
CWE: CWE-250
pull-requests: write권한을 제거하세요.gh pr comment는POST /repos/{owner}/{repo}/issues/{issue_number}/comments를 호출합니다. 이 엔드포인트는 풀 리퀘스트의 일반 댓글에도issues: write권한을 허용합니다. 따라서 이 워크플로에는pull-requests: write가 필요하지 않습니다.포크의
GITHUB_TOKEN이 읽기 전용으로 강등되는 문제는 별도의 토큰 정책입니다. 이 정책은 엔드포인트에 필요한 권한을 변경하지 않습니다.🧰 Tools
🪛 zizmor (1.30.0)
[error] 10-10: overly broad permissions (excessive-permissions): pull-requests: write is overly broad at the workflow level
(excessive-permissions)
🤖 Prompt for AI Agents