Skip to content

Describe a safer pattern to replace pull_request_target - #309

Merged
cottage14 merged 2 commits into
apache:masterfrom
potiuk:gha-replace-pull-request-target
Oct 5, 2026
Merged

cottage14 merged 2 commits into
apache:masterfrom
potiuk:gha-replace-pull-request-target

Conversation

@potiuk

@potiuk potiuk commented Oct 4, 2026

Copy link
Copy Markdown
Member

The policy page tells projects not to use pull_request_target, but it doesn't say what to use instead. From November 2026 the trigger is disabled for ASF repositories, so projects that relied on it need a replacement.

This adds a subsection describing a generic replacement for commenting on, labelling and publishing from fork pull requests:

  • the pull_request build only uploads artifacts;
  • a small pull_request "signal" workflow does nothing except complete, for events that start no build (labels, close);
  • a workflow_run workflow, which always runs from the default branch, holds the write token and consumes the artifacts as data only.

It includes minimal YAML for the signal and privileged workflows, the MUST rules for using the pattern safely (no PR checkout, artifacts as untrusted data, no event values interpolated into run:, explicit workflows: list, least-privilege permissions), and links to a working implementation in apache/magpie-site.

Context: Beam is already reworking its workflows to drop pull_request_target: https://lists.apache.org/thread.html/m2kpyvoq1zcdtosh4s1g4854cxojcdyb

🤖 Generated with Claude Code

Document the build / signal / workflow_run split that lets projects
comment on, label and publish from fork pull requests without
pull_request_target, with an example from apache/magpie-site.

Generated-by: Claude Opus 5
Comment thread content/pages/github-actions-policy.md
@cottage14
cottage14 self-requested a review October 4, 2026 13:41
@cottage14 cottage14 self-assigned this Oct 4, 2026
@potiuk

potiuk commented Oct 4, 2026

Copy link
Copy Markdown
Member Author

Go for it @cottage14 :)

@cottage14 cottage14 left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

github-actions-policy.md

line 39: change the last sentence from passive to active voice: "You can do all of these without 'pull_request_target' by splitting the work across three workflows so that no privileged job ever runs, or even sees, code from the pull request."

line 43: change passive to active voice; "Do the privileged work in workflow_run, which starts when the build workflow or the signal workflow completes. GitHub always runs workflow_run from the default branch, so its code is your reviewed code, never the contributor's. This workflow may hold a write token; and it downloads the artifacts produced by the build and comments, labels or publishes."

line 86: change the comma to a semicolon after 'steps from it'

Line 96: change the part before the URLs to human-readable: "A complete example that publishes website previews of pull requests, including from forks, is in the Apache Magpie website repository:" Consider making the URLs a bulleted list for easier reading.

Use active voice, fix punctuation and list the Magpie example
workflows as bullets.

Generated-by: Claude Opus 5
@potiuk

potiuk commented Oct 4, 2026

Copy link
Copy Markdown
Member Author

@cottage14 thanks for the review! I've applied your suggestions in 65dd6bb:

  • Lines 39 and 43 are now in active voice. On line 43 I used a full stop instead of "; and": "This workflow may hold a write token. It downloads the artifacts…"
  • Line 86: the comma is now a semicolon.
  • Line 96: the intro is now readable text, and the three workflow links are a bulleted list, each with a short description.

Could you take another look?

@potiuk
potiuk requested a review from cottage14 October 4, 2026 23:00

@cottage14 cottage14 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good to me

@cottage14
cottage14 merged commit 7eb7ab3 into apache:master Oct 5, 2026
@potiuk

potiuk commented Oct 5, 2026

Copy link
Copy Markdown
Member Author

🙇 🙇 🙇 🙇 🙇

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants