buildkite / buildkite/docs

Add clarity to build.author conditionals around spoofing

Open
#638 1 comment 0 reactions 0 assignees View on GitHub
Dominant language
Ruby
Stars
59
Forks
313
PR merge metrics
No merged PRs in 30d

Description

[Conditionals](https://buildkite.com/docs/pipelines/conditionals) are a really great feature that we'd like to use, but there was some uncertainty as to where the build.author information comes from. Can we be sure that this data comes from GitHub metadata, and can't be spoofed per-commit?

Adding some additional information to the docs around this would help alleviate concern. Thanks!

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.