You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This workflow may be checking out code in a way that GitHub security tools consider unsafe. That can be dangerous because pull requests from forks are not fully trusted. A malicious contributor could try to modify workflow behavior, access tokens, or abuse permissions if the workflow mixes untrusted pull request code with privileged GitHub Actions permissions.
This does not necessarily mean the repository is currently compromised. It means the workflow has a pattern that security scanners recognize as risky and should be hardened.
Explanation
The Scorecard warning is caused by a checkout step in .github/workflows/on-review.yml using this dynamic ref expression:
Advanced issues are the highest-risk work in this project. We will reject PRs that do not meet these standards.
π Concrete Prerequisites
Advanced Language: Proficient with Python.
Expertise: Deep architectural understanding of _Executable, Transaction, and Query base classes.
Proven History: Successfully completed β₯ 10 intermediate issues in this repo.
Consistency:β₯ 3β4 months of active, human-led contributions to this SDK.
Note
CI/CD Exception: For issues focused on GitHub Actions / Workflows, the repo-specific thresholds above may be waived if the contributor demonstrates advanced-level proficiency in CI/CD.
β οΈ AI Usage Policy
Using AI to generate code for Advanced issues is strictly discouraged
AI may be used to help explain file relationships, but cannot be the main source of research.
Submitting AI-generated or unvalidated code is grounds for immediate closure
β±οΈ Timeline & Workflow
Typical time: ~1 month / ~50 hours.
π΄ Completing an advanced issue in 1β3 days is a red flag and will likely be rejected.
Suggested: Post your proposed architectural approach as a comment and wait for explicit maintainer approval before writing any code.
Testing (unit, integration, mocking, test coverage for edge cases and failure modes)
π‘οΈ Quality & Review Standards
Advanced PRs must be "safe, maintainable, architecturally sound, and production-ready."
Architectural Fit: The solution must fit naturally into the existing SDK abstractions.
Security & Correctness: Evaluate all logic for injection risks, state corruption, or thread-safety issues.
Maintainability: Code must be short and clear enough for any other maintainer to debug without your assistance.
Backward Compatibility: Public API signatures must be preserved. If a breaking change is required, it must be explicitly managed through a deprecation cycle.
Comprehensive Testing: Must include unit and integration tests covering all new logic paths, edge cases, and failure modes. AI generated tests based on AI generated code is grounds for immediate rejection.
β PR Quality Checklist
Before opening your PR, the contributor must confirm:
I have spent the majority of my time researching the problem and solution space extensively, including reviewing relevant code, documentation, and external resources.
I understand the system-wide impact of these changes on affected modules and performance.
The system design fits with current Hiero SDK architectural approaches.
I have tested my changes extensively against both local and network environments.
I have verified naming, types, and field ordering against pinned Protobufs.
Every line of code is personally understood and explainable.
π§βπ¬ Advanced Issue
Welcome! This is an Advanced Issue touching core SDK architecture.
It is designed for expert contributors who have demonstrated deep architectural understanding and a proven track record of high-quality contributions.
π Problem Description
Summary
The Python SDK repository is currently failing the OSSF Scorecard Dangerous-Workflow check with a critical warning.
Scorecard output:
The warning points to this workflow file:
.github/workflows/on-review.yml34This workflow may be checking out code in a way that GitHub security tools consider unsafe. That can be dangerous because pull requests from forks are not fully trusted. A malicious contributor could try to modify workflow behavior, access tokens, or abuse permissions if the workflow mixes untrusted pull request code with privileged GitHub Actions permissions.
Explanation
The Scorecard warning is caused by a checkout step in
.github/workflows/on-review.ymlusing this dynamic ref expression:This pattern is being flagged as an untrusted checkout.
The risk becomes more serious if the workflow is triggered by events such as:
pull_request_targetworkflow_runThe core security concern is this combination:
Depending on the rest of the workflow, this can create risks such as:
GITHUB_TOKENCurrent Behavior
The workflow currently contains a checkout ref that Scorecard identifies as unsafe:
As a result, the repository receives a critical Dangerous-Workflow finding.
Expected Behavior
The workflow should avoid unsafe checkout behavior and clearly separate trusted and untrusted execution contexts.
Expected secure behavior:
π οΈ Implementation Notes
π§ Advanced Contributors β Prerequisites & Expectations
Caution
Advanced issues are the highest-risk work in this project. We will reject PRs that do not meet these standards.
π Concrete Prerequisites
_Executable,Transaction, andQuerybase classes.Note
CI/CD Exception: For issues focused on GitHub Actions / Workflows, the repo-specific thresholds above may be waived if the contributor demonstrates advanced-level proficiency in CI/CD.
β±οΈ Timeline & Workflow
π¬ Technical Domains
.protofiles,_to_proto()/_from_proto()correctness)_require_not_frozen)π‘οΈ Quality & Review Standards
Advanced PRs must be "safe, maintainable, architecturally sound, and production-ready."
β PR Quality Checklist
Before opening your PR, the contributor must confirm:
π Resources & Support
References:
Python SDK References:
π Stuck?