Skip to content

Conversation

@guan404ming
Copy link
Member

No description provided.

@guan404ming guan404ming marked this pull request as draft March 29, 2025 18:51
@jorenham
Copy link
Member

This allows anyone to open a PR that would deploy anything they want to numpy.org. So that'd be a rather big security risk.

@jorenham jorenham closed this Mar 29, 2025
@jorenham
Copy link
Member

in case you want to preview it locally, you can run uv run mkdocs serve, which is probably faster as well.

@guan404ming
Copy link
Member Author

guan404ming commented Mar 30, 2025

I opened this PR is for reviewer.

In most of web related repo (like https://github.com/shadcn-ui/ui, https://github.com/ant-design/ant-design), it would deploy the preview site for that PR where reviewer could easily review the code change toward UI. However, the preview site would be deployed only after the approval of the repo owner. (thus prevent the security issue). Also, some repo even have their preview domain to separate the production and staging env.

Do you think that it's needed here?

@jorenham
Copy link
Member

Hm ok it might not be as bad as I thought. But still, it feel like the risks outweigh the benefit to me.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants