Those who’re here because of the miner’s attacks, here’s my approach:
- Lock the conversation. (otherwise, the miner will reopen the PR)
- Block the user. (so that no more PRs could be opened)
- Cancel workflows (so that your Actions aren’t mining for someone’s wallet)
- Report about the user (to let GH ban it sooner)
I recommend this exact ordering.