Yes, it's a security feature:
https://github.blog/news-insights/product-news/github-actions-improvements-for-fork-and-pull-request-workflows/
_-> new pull_request_target event [...] runs against the workflow and code
from the base of the pull request. This means the workflow is running from a
trusted source and is given access to a read/write token as well as secrets
enabling the maintainer to safely comment on or label a pull request._
--
Reply to this email directly or view it on GitHub:
https://github.com/openstreetmap/openstreetmap-website/issues/5267#issuecomment-2429954750
You are receiving this because you are subscribed to this thread.
Message ID:
<openstreetmap/openstreetmap-website/issues/5267/2429954...@github.com>
_______________________________________________
rails-dev mailing list
rails-dev@openstreetmap.org
https://lists.openstreetmap.org/listinfo/rails-dev