Steve Dower <steve.do...@python.org> added the comment:
> first-time contributors need a maintainer to approve the workflows for their > PRs This is an important security consideration, so I'd rather not go and change it. On the main request, provided the workflow_dispatch is only triggerable by non-contributors in their own fork (without any of our tokens/etc.) then it's fine by me. If it allows anyone to trigger CI builds against the main repo, I'd rather not. ---------- _______________________________________ Python tracker <rep...@bugs.python.org> <https://bugs.python.org/issue44972> _______________________________________ _______________________________________________ Python-bugs-list mailing list Unsubscribe: https://mail.python.org/mailman/options/python-bugs-list/archive%40mail-archive.com