Add clarity to build.author conditionals around spoofing
Open
- Dominant language
- Ruby
- Stars
- 59
- Forks
- 313
- PR merge metrics
- No merged PRs in 30d
Description
[Conditionals](https://buildkite.com/docs/pipelines/conditionals) are a really great feature that we'd like to use, but there was some uncertainty as to where the build.author information comes from. Can we be sure that this data comes from GitHub metadata, and can't be spoofed per-commit?
Adding some additional information to the docs around this would help alleviate concern. Thanks!
Contributor guide
Assessment
This issue has not been assessed yet.