Skip to content

fix: sidebar reminder#373

Open
scode2277 wants to merge 1 commit intodevelopfrom
chore/fix-reminder
Open

fix: sidebar reminder#373
scode2277 wants to merge 1 commit intodevelopfrom
chore/fix-reminder

Conversation

@scode2277
Copy link
Collaborator

This workflow now uses pull_request_target so it can also comment on PRs from forks too(with just pull_request, fork PRs don't have write permissions to post comments).

This doesn't open any attack vectors as the workflow never checks out code; it only reads file metadata from the GitHub API to see if any files in docs/pages were added, renamed, or deleted.

Also hardened the filename sanitization to strip Unicode direction overrides

Frameworks PR Checklist

Thank you for contributing to the Security Frameworks! Before you open a PR, make sure to read information for contributors and take a look at the following checklist:

  • Describe your changes, substitute this text with the information
  • If you are touching an existing piece of content, tag current contributors from the attribution list
  • If there is a steward for that framework, ask the steward to review it
  • If you're modifying the general outline, make sure to update it in the vocs.config.ts adding the dev: true parameter
  • If you need feedback for your content from the wider community, share the PR in our Discord
  • Review changes to ensure there are no typos, see instructions below

@scode2277 scode2277 requested a review from mattaereal February 12, 2026 15:28
@vercel
Copy link

vercel bot commented Feb 12, 2026

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
frameworks Ready Ready Preview, Comment Feb 12, 2026 3:28pm

Request Review

@scode2277 scode2277 added local setup Improvements or additions to the local setup fix This PR fixes a bug or resolves an issue labels Feb 12, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

fix This PR fixes a bug or resolves an issue local setup Improvements or additions to the local setup

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant