Skip to content

Access denied: Potential confused deputy attack detected. Actor '<account_name>' does not match the event author. The workflow may have been triggered indirectly via a bot command. #39871

@maikelvdh

Description

@maikelvdh

When having frontmatter configuration like:

on:
  pull_request:
    types: [opened, reopened, synchronize]

We are noticing on events like: PR Release Notes #1: Pull request https://github.com/<org>/<repo>/pull/1 synchronize by <actor_name> the following error in pre-activation:

Access denied: Potential confused deputy attack detected. Actor '<actor_name>' does not match the event author. The workflow may have been triggered indirectly via a bot command.

The <actor_name> is matching 100% in both the event and error message.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions