Events and triggers #11
|
What's the difference between pull_request and pull_request_target triggers, and why might using the wrong one be a security issue? |
Replies: 1 comment
pull_request vs pull_request_target pull_request Runs code from the fork/feature branch Runs code from the base branch (but the workflow file itself is from the base branch too) A repository uses pull_request_target in a workflow that does something like: yaml The workflow runs in the base repository's context with access to secrets, but the attacker controls the code that gets executed (e.g., a malicious package.json or postinstall script).. The root issue: pull_request_target gives the workflow privileged access (write token, secrets), but if you then check out and execute the PR's code, you're running untrusted code with trusted credentials. Safe usage of pull_request_target: Only use it for workflows that do not check out and execute the PR's code — for example, adding labels, posting comments, or running checks that only look at PR metadata |
pull_request vs pull_request_target
Both trigger workflows on pull request events, but they differ in what context the workflow runs under, which determines what permissions and secrets are available.
pull_request
The workflow runs in the merge commit of the PR's branch, using the workflow from the PR's base branch. It has read-only token permissions by default and cannot access secrets from the target repository.
Runs code from the fork/feature branch
Uses the workflow definition from the base branch (for security)
Token has read-only permissions
No access…