pull_request events from forks/branches cannot access repo secrets, causing 401 auth failures on every PR triage. pull_request_target runs in the base repo context. Safe because the workflow only reads event payload data and sparse-checks base branch docs — no PR code executes. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| ISSUE_TEMPLATE | ||
| workflows | ||
| FUNDING.yml | ||
| PULL_REQUEST_TEMPLATE.md | ||