Skip to content

Safe-outputs add_comment mentions sanitization being too restrictive #40345

@ivancea

Description

@ivancea

Currently, add_comment sanitization requires to list all members that may be mentioned.
This is too restrictive, and doesn't allow organizations to freely mention their own engineers.

A few possible solutions:

  • Allow full teams by just declaring the team name
  • Configuration to disable sanitization for mentions, as a fallback

Metadata

Metadata

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions