Public repositories
Why jobs from public repositories are refused by default, how to allow one, and which runs are refused even then.
On a public repository, anyone can open a pull request, and a pull request can change what a workflow runs. A runner in your cloud account is not a place for a stranger’s code. So SuperCI refuses jobs from public repositories unless you allow them.
Allow a repository
Workflows → Limits → Public repositories. Add the repositories whose jobs may run, one by one.
What is refused even then
On an allowed public repository, two kinds of runs are still refused:
- runs from a fork’s pull request;
- runs triggered by
pull_request_target.
Both let code from outside the repository run with more than it should have. A refused job fails at once on GitHub with the reason; it does not wait.
Organizations
On an organization, GitHub’s default runner group also keeps self-hosted runners away from public repositories. If you allow one in SuperCI and its jobs still do not start, check the runner group’s settings on GitHub.