Skip to content

ci: block Claude from running on outside-contributor fork PRs - #648

Open
uripe-wix wants to merge 1 commit into
base44:mainfrom
uripe-wix:harden/claude-fork-pr-guard
Open

uripe-wix wants to merge 1 commit into
base44:mainfrom
uripe-wix:harden/claude-fork-pr-guard

Conversation

@uripe-wix

Copy link
Copy Markdown

What

Gate the Claude workflow so it only runs when the PR/issue author is a repo member (OWNER/MEMBER/COLLABORATOR), by adding an author_association check to the existing if:.

Why

On a fork PR from an outside contributor, tagging @claude makes claude-code-action check out the fork head and run its install/build scripts (bun install / npm install run the PR-supplied package.json). Because the job passes no github_token, the action mints a token from the Claude GitHub App install via OIDC, which on this org is granted contents/pull_requests/issues/workflows = write — so the job's contents: read does not bound it. The action's own docs confirm package.json/lockfiles stay at the PR head.

The write-access check in the action is on the commenter, so a maintainer tagging @claude on an outsider's fork PR passes it. Gating on the PR/issue author instead blocks the agent from acting on untrusted fork code. Members' own PRs are unaffected.

Tradeoff: @claude will no longer act on PRs opened by non-members. For assisting outside contributors, the action docs recommend passing a read-only github_token (+ secret scrub / tool caps) rather than the write App token.

Nothing else in the workflow changes.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant