Make FormatCheck safe for fork PRs (pull_request trigger)#2
Merged
Conversation
The reusable FormatCheck workflow was designed to be called from a `pull_request_target` trigger and checked out the PR head from the fork repository. GitHub now refuses to check out fork PR code from a `pull_request_target` workflow (the "pwn request" hardening), which broke formatting checks for external contributors. Rework the workflow to be called from a `pull_request` trigger instead: - Reduce permissions to `contents: read` (no write token needed). - Drop the PR-comment steps, which would 403 under a fork's read-only token. - Report the required formatting diff and `git runic` instructions in the job summary, and fail the job so it surfaces as a red check. Consumers must switch their trigger from `pull_request_target` to `pull_request`; downstream PRs accompany this change. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This was referenced Jul 24, 2026
Merged
Merged
Merged
Merged
Open
Merged
Merged
Merged
lkdvos
added a commit
to QuantumKitHub/TensorKitTensors.jl
that referenced
this pull request
Jul 24, 2026
Switches the Format workflow trigger from `pull_request_target` to `pull_request` and drops the `actions: write` / `pull-requests: write` permissions. GitHub now refuses to check out fork PR code from a `pull_request_target` workflow, which broke the formatting check for all external contributors (PRs from forks). The reusable workflow has been reworked to run safely under a read-only `pull_request` context and reports the formatting diff in the job summary instead of commenting on the PR. Depends on QuantumKitHub/QuantumKitHubActions#2 (the reusable workflow update), which should be merged first since this references `FormatCheck.yml@main`. Refs QuantumKitHub/.github#2 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Reworks the reusable
FormatCheck.ymlso formatting checks work for externalcontributors again.
Previously the workflow was called from a
pull_request_targettrigger andchecked out the PR head from the fork. GitHub now refuses to check out fork PR
code from a
pull_request_targetworkflow, breaking the check for all fork PRs.Changes:
contents: read(no write token needed).git runicinstructions in the job summary andfail the job so it surfaces as a red check.
Consumers must switch their trigger from
pull_request_targettopull_request;those PRs accompany this one and are tracked in QuantumKitHub/.github#2.
Merge this before the consumer PRs, since consumers reference
FormatCheck.yml@main.Refs QuantumKitHub/.github#2
🤖 Generated with Claude Code