Public repositories

Why jobs from public repositories are refused by default, how to allow one, and which runs are refused even then.

On a public repository, anyone can open a pull request, and a pull request can change what a workflow runs. A runner in your cloud account is not a place for a stranger’s code. So SuperCI refuses jobs from public repositories unless you allow them.

Allow a repository

Workflows → Limits → Public repositories. Add the repositories whose jobs may run, one by one.

What is refused even then

On an allowed public repository, two kinds of runs are still refused:

  • runs from a fork’s pull request;
  • runs triggered by pull_request_target.

Both let code from outside the repository run with more than it should have. A refused job fails at once on GitHub with the reason; it does not wait.

Organizations

On an organization, GitHub’s default runner group also keeps self-hosted runners away from public repositories. If you allow one in SuperCI and its jobs still do not start, check the runner group’s settings on GitHub.