]> git-server-git.apps.pok.os.sepia.ceph.com Git - ceph.git/commit
.github/workflows: switch to pull_request_target trigger 70690/head
authorPatrick Donnelly <pdonnell@ibm.com>
Thu, 30 Jul 2026 00:43:02 +0000 (20:43 -0400)
committerPatrick Donnelly <pdonnell@ibm.com>
Thu, 30 Jul 2026 00:43:02 +0000 (20:43 -0400)
commit71ddab8e3266459c28f6429a585ce8507aed30b4
tree398ae186b0ea47db1c9e6f9b9c38457fdd1ca736
parente82ccd0873677ffd0cac1d081ecdea512dbc05bd
.github/workflows: switch to pull_request_target trigger

Switch the trigger from `pull_request` to `pull_request_target` so that
the workflow definition on `main` is evaluated for PRs targeting active
release branches (main, umbrella, tentacle, squid). This allows the check
to run cleanly across release branches without requiring workflow file
backports to each branch.

While this workflow passes `github.token`, the token permissions are
strictly restricted to read-only (`contents: read` and `pull-requests: read`).
Because no PR code is checked out or executed, using `pull_request_target`
presents zero security risk here.

Signed-off-by: Patrick Donnelly <pdonnell@ibm.com>
.github/workflows/check-license.yml