Skip to content

Remove vulnerable PR-comment artifact pattern - #64

Merged
maxulysse merged 1 commit into
masterfrom
patch
Sep 14, 2026
Merged

maxulysse merged 1 commit into
masterfrom
patch

Conversation

@mashehu

@mashehu mashehu commented Jul 24, 2026

Copy link
Copy Markdown
Contributor

Security patch

This PR applies a security fix included in nf-core/tools 4.0.3 for a potential exploit in the GitHub Actions workflows that post comments on pull requests.

For details, see the related security advisory: GHSA-rpx5-723p-jrgj.

The fix must be merged into the default branch (main or master) to take effect. Please merge this PR as soon as possible.

These changes only affect CI workflows, so merging them into the default branch does not require a new pipeline release.

@github-actions

Copy link
Copy Markdown

nf-core pipelines lint overall result: Passed ✅ ⚠️

Posted for pipeline commit 6a733f6

+| ✅ 205 tests passed       |+
#| ❔   4 tests were ignored |#
!| ❗   3 tests had warnings |!
Details

❗ Test warnings:

  • pipeline_todos - TODO string in CONTRIBUTING.md: Add any pipeline specific contribution guidelines here, such as coding styles, procedures, checklists etc.
  • pipeline_if_empty_null - ifEmpty(null) found in /home/runner/work/demo/demo/lint_results.md: _* pipeline_if_empty_null - No ifEmpty(null) strings found
    _
  • included_configs - Pipeline config does not include custom configs. Please add the includeConfig line.

❔ Tests ignored:

  • files_exist - File is ignored: .github/workflows/linting_comment.yml
  • files_unchanged - File ignored due to lint config: .github/workflows/branch.yml
  • files_unchanged - File does not exist: .github/workflows/linting_comment.yml
  • files_unchanged - File ignored due to lint config: .github/workflows/linting.yml

✅ Tests passed:

Run details

  • nf-core/tools version 4.0.2
  • Run at 2026-07-24 09:59:55

@maxulysse
maxulysse merged commit 555d145 into master Sep 14, 2026
18 checks passed
@maxulysse
maxulysse deleted the patch branch September 14, 2026 09:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants