Hmmm,

thinking about it ... this is not quite "safe" is it? Just imagining someone 
starting PRs with maven download-plugin and exec-plugin starting a bitcoin 
miner or worse ... what does Infra think about this?
Would prefer the "everyone" PR builds to run on Travis or something that 
wouldn't harm the ASF.

Chris



Am 03.01.19, 16:37 schrieb "Allen Wittenauer" 
<a...@effectivemachines.com.INVALID>:

    
    
    > On Jan 3, 2019, at 7:34 AM, Christofer Dutz <christofer.d...@c-ware.de> 
wrote:
    > 
    > Hi Allen,
    > 
    > thanks for that ... if I had known that simply selecting the "GitHub" as 
source instead of the generic "Git" ... would have made things easier ... 
however it seems that we have exceeded some sort of API usage limit:
    
    Yup.  That’s why we set up our own project-specific user to query GitHub 
and set trust to ‘Everyone’ since our user doesn’t have privs on Github. :/
    
    (See also: last month’s discussion of github’s idiotic permission system.)
    
    
    

Reply via email to