From: Patrick Donnelly Date: Thu, 30 Jul 2026 00:43:02 +0000 (-0400) Subject: .github/workflows: switch to pull_request_target trigger X-Git-Url: http://git-server-git.apps.pok.os.sepia.ceph.com/?a=commitdiff_plain;h=71ddab8e3266459c28f6429a585ce8507aed30b4;p=ceph.git .github/workflows: switch to pull_request_target trigger Switch the trigger from `pull_request` to `pull_request_target` so that the workflow definition on `main` is evaluated for PRs targeting active release branches (main, umbrella, tentacle, squid). This allows the check to run cleanly across release branches without requiring workflow file backports to each branch. While this workflow passes `github.token`, the token permissions are strictly restricted to read-only (`contents: read` and `pull-requests: read`). Because no PR code is checked out or executed, using `pull_request_target` presents zero security risk here. Signed-off-by: Patrick Donnelly --- diff --git a/.github/workflows/check-license.yml b/.github/workflows/check-license.yml index 9dc48b6aa302..b40394e049ab 100644 --- a/.github/workflows/check-license.yml +++ b/.github/workflows/check-license.yml @@ -1,6 +1,12 @@ --- name: "Check for Incompatible Licenses" -on: [pull_request] +on: + pull_request_target: + branches: + - main + - umbrella + - tentacle + - squid permissions: contents: read