diff --git a/.github/workflows/vulnerable.yml b/.github/workflows/vulnerable.yml new file mode 100644 index 0000000..f609898 --- /dev/null +++ b/.github/workflows/vulnerable.yml @@ -0,0 +1,23 @@ +on: pull_request_target + +jobs: + build: + name: Build and test + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v2 + with: + ref: ${{ github.event.pull_request.head.sha }} + + - uses: actions/setup-node@v1 + - run: | + npm install + npm build + - uses: completely/fakeaction@v2 + with: + arg1: ${{ secrets.supersecret }} + + - uses: fakerepo/comment-on-pr@v1 + with: + message: | + Thank you!