A user with expired credentials can receive tokens and bypass restrictions because credentials check is not enforced in the transfer hook as it is done in the deposit hook #1179
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
name: Repo Moderator | |
on: | |
issues: | |
types: [labeled, unlabeled, closed, reopened, assigned, unassigned] | |
pull_request: | |
types: [closed, reopened, assigned, unassigned] | |
jobs: | |
revert-action: | |
if: ${{ !startsWith(github.actor, 'C4-') }} && ${{ !startsWith(github.actor, 'C4-') }} && github.actor != 'howlbot-integration' | |
runs-on: ubuntu-latest | |
steps: | |
- uses: actions/checkout@v4 | |
- name: Revert Label Changes | |
uses: code-423n4/repo-moderator@main | |
with: | |
github-token: ${{ secrets.ACTIONS_TOKEN }} | |
sponsor-team-slug: "2024-08-wildcat-sponsors" | |
allowed-labels: "sponsor confirmed, sponsor disputed, sponsor acknowledged" |