Skip to content

Make FormatCheck safe for fork PRs (pull_request trigger)#2

Merged
lkdvos merged 1 commit into
mainfrom
format-check-safe-fork-prs
Jul 24, 2026
Merged

Make FormatCheck safe for fork PRs (pull_request trigger)#2
lkdvos merged 1 commit into
mainfrom
format-check-safe-fork-prs

Conversation

@lkdvos

@lkdvos lkdvos commented Jul 24, 2026

Copy link
Copy Markdown
Member

Reworks the reusable FormatCheck.yml so formatting checks work for external
contributors again.

Previously the workflow was called from a pull_request_target trigger and
checked out the PR head from the fork. GitHub now refuses to check out fork PR
code from a pull_request_target workflow, breaking the check for all fork PRs.

Changes:

  • Reduce permissions to contents: read (no write token needed).
  • Drop the PR-comment steps, which would 403 under a fork's read-only token.
  • Report the formatting diff + git runic instructions in the job summary and
    fail the job so it surfaces as a red check.

Consumers must switch their trigger from pull_request_target to pull_request;
those PRs accompany this one and are tracked in QuantumKitHub/.github#2.

Merge this before the consumer PRs, since consumers reference FormatCheck.yml@main.

Refs QuantumKitHub/.github#2

🤖 Generated with Claude Code

The reusable FormatCheck workflow was designed to be called from a
`pull_request_target` trigger and checked out the PR head from the fork
repository. GitHub now refuses to check out fork PR code from a
`pull_request_target` workflow (the "pwn request" hardening), which broke
formatting checks for external contributors.

Rework the workflow to be called from a `pull_request` trigger instead:

- Reduce permissions to `contents: read` (no write token needed).
- Drop the PR-comment steps, which would 403 under a fork's read-only token.
- Report the required formatting diff and `git runic` instructions in the
  job summary, and fail the job so it surfaces as a red check.

Consumers must switch their trigger from `pull_request_target` to
`pull_request`; downstream PRs accompany this change.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This was referenced Jul 24, 2026
@lkdvos
lkdvos merged commit e3f4c85 into main Jul 24, 2026
@lkdvos
lkdvos deleted the format-check-safe-fork-prs branch July 24, 2026 15:30
lkdvos added a commit to QuantumKitHub/TensorKitTensors.jl that referenced this pull request Jul 24, 2026
Switches the Format workflow trigger from `pull_request_target` to
`pull_request` and drops the `actions: write` / `pull-requests: write`
permissions.

GitHub now refuses to check out fork PR code from a
`pull_request_target`
workflow, which broke the formatting check for all external contributors
(PRs from forks). The reusable workflow has been reworked to run safely
under a
read-only `pull_request` context and reports the formatting diff in the
job
summary instead of commenting on the PR.

Depends on QuantumKitHub/QuantumKitHubActions#2 (the reusable workflow
update),
which should be merged first since this references
`FormatCheck.yml@main`.

Refs QuantumKitHub/.github#2

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant