Repository navigation
Replace deprecated readthedocs/actions/preview #587
Description
Activity
I’m happy to do this if no one else is doing it.
Auto-bot-comment spam on PRs is very annoying. Can we keep the feature of only adding a couple of lines to the PR body itself?
A
Reacted by Stan Ulbrych and Petr ViktorinGiven that:
pull_request_targetcan be insecurepull_request_targetwas exploited in the (ongoing?) Shai-Hulud 2 attack- For example, see "Why did it happen?" at https://posthog.com/blog/nov-24-shai-hulud-attack-post-mortem
- despite GitHub making it simpler soon, it still wouldn't have prevented all of the attack, and GitHub admits there's still an elevated risk
- reasoning about these edge cases is complex, it's easier to replace
pull_request_target - we already have plenty of bots commenting (Bedevere, Miss Islington, CLA bot) on
cpythonPRs
I'm in favour replacing the workflows with the app, to at least test it out.
Otherwise, let's just remove the workflows. We can still access the docs preview via the status checks, although less convenient.
cc @sethmlarson re: security stuff
Reacted by Seth Larson@hugovk @ezio-melotti Thanks for the analysis, yes let's remove this deprecated workflow and replace it with the application if that's a suitable replacement.
Reacted by Hugo van KemenadeReacted by Ezio MelottiPR for the devguide: python/devguide#1713
Let's continue with this.
@JacobCoffee I've invited you to https://app.readthedocs.org/projects/pep-previews/ and https://app.readthedocs.org/projects/python-docs-theme-previews/
No rush, please could you also migrate those?
I don't have access to https://app.readthedocs.org/projects/docs-community/
@AA-Turner Please could you add
JacobCoffeeandhugovk?Reacted by Seth LarsonPlease could you add
JacobCoffeeandhugovk?I've added you.
Reacted by Hugo van KemenadeSorry for the delay! Thanks Petr, looks like Hugo has accepted and the invitation has been sent to Jacob.
A
Reacted by Hugo van KemenadeLet's also do CPython now as well, we don't need to wait longer. This one can be first.
@JacobCoffee I've invited you to https://app.readthedocs.org/projects/cpython-previews/
Reacted by Seth Larson, Manuel Kaufmann and Zachary Waretried this today, only seeing devguide as admin-able projects @hugovk - maybe invites expired? sorry about htat
Yeah, they only last two weeks. No problem, re-sent! And for the others, but CPython is most important. Thanks!
these are all done now on the RtD side, sorry for delay
individual repos will need their GHA workflows updated when available
Reacted by Hugo van KemenadeReacted by Seth LarsonThanks!
Removing the old workflow:
All done, thanks all!
Reacted by Ezio Melotti

As I was reviewing the
python/cpythonworkflows for security issues, I noticed thatdocumentation-links.ymlusespull_request_target, which is potentially dangerous:pull_request_targettrigger readthedocs/actions#45This is apparently required by
readthedocs/actions/previewin order to edit the first PR message and add the link to the doc preview.However I also noticed that
readthedocs/actions/previewis now deprecated and that its README states:Warning
This action is deprecated and it shouldn't be used.
This feature was included in the Read the Docs application itself.
For more information, check our documentation.
As an alternative they suggest to connect their GitHub app and use that instead. Instead of editing the first comment, the app will add a comment which will list and link to changed/added/deleted files.
Note that the app is still in beta.
If we switch to the app we can stop using the deprecated action get rid of the
documentation-links.ymlworkflow andpull_request_targetuse.I brought this up to @hugovk attention, and he suggested to try the app on one of the other (smaller) repos first:
devguide: devguide#1713pepspython-docs-themedocs-communityIf it works fine and we are happy with it, we can then update all the other repos (including
cpython).cpythoncc @humitos