Skip to content

Commit

Permalink
Add a note saying that PR/MR URLs are not a good idea
Browse files Browse the repository at this point in the history
  • Loading branch information
cweagans committed Jul 1, 2023
1 parent cfdf817 commit a43a186
Showing 1 changed file with 6 additions and 0 deletions.
6 changes: 6 additions & 0 deletions docs/usage/defining-patches.md
Expand Up @@ -11,6 +11,12 @@ You can describe patches to the plugin in one of two ways: the compact format or
In any of the following examples, you can specify a path relative to the root of your project instead of a web address.
{{< /callout >}}

{{< warning title="Avoid using patches autogenerated by PR/MR URLs" >}}
The contents of these patches can change by pushing more commits to a pull request or merge request. A malicious user
could abuse this behavior to cause you to deploy code that you didn't mean to deploy. If you must use a PR/MR as the
basis for a patch, download the patch, include it in your project, and apply the patch using the local path instead.
{{< /warning >}}

### Compact format

```json
Expand Down

0 comments on commit a43a186

Please sign in to comment.