From 5f59dce0c7ca84ad62fbfc1c941564a0ff44b02f Mon Sep 17 00:00:00 2001 From: Gauvino Date: Mon, 1 Jun 2026 20:14:24 +0200 Subject: [PATCH] fix(pr-validation): run under pull_request_target + drop DoS-prone comment loop Security audit fixes: - The jobs gated on github.event_name == 'pull_request' but the trigger is pull_request_target, so they never ran (validation was silently disabled). Gate on 'pull_request_target'. - Replace the loop-until-stable HTML-comment strip with a single linear pass (+ trailing-unterminated strip): still leaves no /g, ""); - } while (out !== prev); - return out.replace(/` +// blocks, then drop any leftover unterminated `/g, "") + .replace(/