diff --git a/.github/workflows/approve-contributor.yml b/.github/workflows/approve-contributor.yml index 665128b..68cc7fd 100644 --- a/.github/workflows/approve-contributor.yml +++ b/.github/workflows/approve-contributor.yml @@ -9,9 +9,12 @@ on: jobs: approve: - # Only comments that might approve someone join the queue, and they run one - # at a time so two lgtm replies can't race on APPROVED_CONTRIBUTORS. - if: contains(github.event.comment.body, 'lgtm') # contains() ignores case + # Only maintainers' comments that might approve someone join the queue, and + # they run one at a time so two lgtm replies can't race on APPROVED_CONTRIBUTORS. + # (The script below still checks for write access.) + if: >- + contains(github.event.comment.body, 'lgtm') && + contains(fromJSON('["OWNER", "MEMBER", "COLLABORATOR"]'), github.event.comment.author_association) concurrency: group: approve-contributor cancel-in-progress: false diff --git a/site/lib/feedback.js b/site/lib/feedback.js index 91df858..d697474 100644 --- a/site/lib/feedback.js +++ b/site/lib/feedback.js @@ -20,11 +20,13 @@ const oneLine = (value, max) => String(value ?? "").replace(/\s+/g, " ").trim(). // Mentions in someone else's text would ping strangers, and issue references // (#1, owner/repo#1, GH-1, github.com links) would add backlinks to other // people's issues, so break them all with a zero-width space. Escaping & first -// stops @ and # from turning back into @ and # when GitHub renders. +// stops @ and # from turning back into @ and # when GitHub renders, +// and escaping < keeps out raw HTML such as an unclosed