Conversation
Make the gap in enterprise IP restrictions clearer (this clarification also helps AI responses understand the security gap this creates). (I'd prefer that the IP restrictions were applied to forks too - but this will suffice for now).
How to review these changes 👓Thank you for your contribution. To review these changes, choose one of the following options: A Hubber will need to deploy your changes internally to review. Table of review linksNote: Please update the URL for your staging server or codespace. The table shows the files in the Key: fpt: Free, Pro, Team; ghec: GitHub Enterprise Cloud; ghes: GitHub Enterprise Server 🤖 This comment is automatically generated. |
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
The security-sensitive claim about fork access needs subject-matter confirmation before publication.
Review effort: Balanced
Findings: None
What changed in this PR
Updates shared IP allow-list documentation to clarify the stated exception for repository forks owned by non-managed users.
Changes:
- Adds user-owned forks to the list of resources not restricted by IP allow lists, excluding managed user accounts.
| File | Description |
|---|---|
| data/reusables/identity-and-permissions/ip-allow-lists-which-resources-are-protected.md | Documents the user-owned fork exception. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Make the gap in enterprise IP restrictions clearer (this clarification also helps AI responses understand the security gap this creates).
(I'd prefer that the IP restrictions were applied to forks too - but this will suffice for now).
Why:
Closes: the lack of clarity around IP restrictions not applying to the forks of enterprise repositories.
No issue. This stands alone.
What's being changed (if available, include any code snippets, screenshots, or gifs):
Check off the following: