This is an automated email from the ASF dual-hosted git repository.

damccorm pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/beam.git


The following commit(s) were added to refs/heads/master by this push:
     new 985c8fa0a01 Migrate 7 pilot CI workflows from pull_request_target to 
pull_request (#40360)
985c8fa0a01 is described below

commit 985c8fa0a01de9fd4004d269133a388775aafc0b
Author: Danny McCormick <[email protected]>
AuthorDate: Thu Oct 1 14:26:58 2026 +0000

    Migrate 7 pilot CI workflows from pull_request_target to pull_request 
(#40360)
---
 .github/actions/setup-action/action.yml       | 2 +-
 .github/build.gradle                          | 4 ++--
 .github/workflows/beam_PostCommit_Go.yml      | 6 +++---
 .github/workflows/beam_PostCommit_Javadoc.yml | 6 +++---
 .github/workflows/beam_PreCommit_GHA.yml      | 6 +++---
 .github/workflows/beam_PreCommit_Go.yml       | 6 +++---
 .github/workflows/beam_PreCommit_Java.yml     | 9 +++++----
 .github/workflows/beam_PreCommit_Python.yml   | 7 ++++---
 .github/workflows/beam_PreCommit_RAT.yml      | 6 +++---
 9 files changed, 27 insertions(+), 25 deletions(-)

diff --git a/.github/actions/setup-action/action.yml 
b/.github/actions/setup-action/action.yml
index 4c4bb275319..4ca21945b12 100644
--- a/.github/actions/setup-action/action.yml
+++ b/.github/actions/setup-action/action.yml
@@ -42,7 +42,7 @@ runs:
         PHRASE: "${{ github.event.comment.body }}"
     - name: Check out repository code if pull request commit
       shell: bash
-      if: ${{ github.event_name == 'pull_request_target' }}
+      if: ${{ github.event_name == 'pull_request' || github.event_name == 
'pull_request_target' }}
       run: |
           # GitHub will automatically generate a merge commit when there are 
no merge conflicts.
           # We first try to check that out, and fall back to checking out the 
tip of the pull request branch.
diff --git a/.github/build.gradle b/.github/build.gradle
index d5a9a6c9dc7..e0243e2f81b 100644
--- a/.github/build.gradle
+++ b/.github/build.gradle
@@ -50,10 +50,10 @@ task check {
       if ( fname.startsWith("beam_PreCommit") || 
fname.startsWith("beam_PostCommit") ) {
         List paths
         try {
-          paths = workflow.getAt(true).pull_request_target.paths as List
+          paths = (workflow.getAt(true).pull_request ?: 
workflow.getAt(true).pull_request_target).paths as List
         } catch (Exception e) {
           errors.add("Fail to get the trigger path for ${fname}. " +
-                    "Make sure it has a pull_request_target trigger.")
+                    "Make sure it has a pull_request or pull_request_target 
trigger.")
           return
         }
 
diff --git a/.github/workflows/beam_PostCommit_Go.yml 
b/.github/workflows/beam_PostCommit_Go.yml
index 74c9930816c..7f0afe9d9ee 100644
--- a/.github/workflows/beam_PostCommit_Go.yml
+++ b/.github/workflows/beam_PostCommit_Go.yml
@@ -18,11 +18,11 @@ name: PostCommit Go
 on:
   schedule:
     - cron: '30 3/6 * * *'
-  pull_request_target:
+  pull_request:
     paths: ['release/trigger_all_tests.json', 
'.github/trigger_files/beam_PostCommit_Go.json']
   workflow_dispatch:
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: read
@@ -52,7 +52,7 @@ jobs:
   beam_PostCommit_Go:
     if: |
       github.event_name == 'workflow_dispatch' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event.comment.body == 'Run Go PostCommit'
     runs-on: [self-hosted, ubuntu-24.04, main]
diff --git a/.github/workflows/beam_PostCommit_Javadoc.yml 
b/.github/workflows/beam_PostCommit_Javadoc.yml
index 2ed3777d151..25093813031 100644
--- a/.github/workflows/beam_PostCommit_Javadoc.yml
+++ b/.github/workflows/beam_PostCommit_Javadoc.yml
@@ -20,7 +20,7 @@ name: PostCommit Javadoc
 on:
   schedule:
     - cron: '0 5/6 * * *'
-  pull_request_target:
+  pull_request:
     paths: ['release/trigger_all_tests.json', 
'.github/trigger_files/beam_PostCommit_Javadoc.json']
   workflow_dispatch:
 
@@ -29,7 +29,7 @@ concurrency:
   group: '${{ github.workflow }} @ ${{ github.event.pull_request.number || 
github.sha || github.head_ref || github.ref }}-${{ github.event.schedule || 
github.event.comment.id || github.event.sender.login }}'
   cancel-in-progress: true
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: read
@@ -61,7 +61,7 @@ jobs:
         job_phrase: [Run Javadoc PostCommit]
     if: |
       github.event_name == 'workflow_dispatch' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event.comment.body == 'Run Javadoc PostCommit'
     steps:
diff --git a/.github/workflows/beam_PreCommit_GHA.yml 
b/.github/workflows/beam_PreCommit_GHA.yml
index 96fd5426d7c..684d1f4465a 100644
--- a/.github/workflows/beam_PreCommit_GHA.yml
+++ b/.github/workflows/beam_PreCommit_GHA.yml
@@ -20,7 +20,7 @@ on:
     tags: ['v*']
     branches: ['master', 'release-*']
     paths: ['.github/**/*.yml']
-  pull_request_target:
+  pull_request:
     branches: ['master', 'release-*' ]
     paths: ['.github/**/*.yml', 'release/trigger_all_tests.json', 
'.github/trigger_files/beam_PreCommit_GHA.json']
   issue_comment:
@@ -29,7 +29,7 @@ on:
   - cron: '0 */6 * * *'
   workflow_dispatch:
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: read
@@ -66,7 +66,7 @@ jobs:
     timeout-minutes: 30
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event_name == 'workflow_dispatch' ||
       github.event.comment.body == 'Run GHA PreCommit'
diff --git a/.github/workflows/beam_PreCommit_Go.yml 
b/.github/workflows/beam_PreCommit_Go.yml
index 335d531f743..f992cb9118f 100644
--- a/.github/workflows/beam_PreCommit_Go.yml
+++ b/.github/workflows/beam_PreCommit_Go.yml
@@ -20,7 +20,7 @@ on:
     tags: ['v*']
     branches: ['master', 'release-*']
     paths: ['model/**', 'sdks/go.mod', 'sdks/go.sum', 'sdks/go/**', 
'release/**', '.github/workflows/beam_PreCommit_Go.yml']
-  pull_request_target:
+  pull_request:
     branches: ['master', 'release-*']
     paths: ['model/**', 'sdks/go.mod', 'sdks/go.sum', 'sdks/go/**', 
'release/**', 'release/trigger_all_tests.json', 
'.github/trigger_files/beam_PreCommit_Go.json']
   issue_comment:
@@ -29,7 +29,7 @@ on:
     - cron: '0 1/6 * * *'
   workflow_dispatch:
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: read
@@ -66,7 +66,7 @@ jobs:
     timeout-minutes: 120
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event_name == 'workflow_dispatch' ||
       github.event.comment.body == 'Run Go PreCommit'
diff --git a/.github/workflows/beam_PreCommit_Java.yml 
b/.github/workflows/beam_PreCommit_Java.yml
index ddfbec257a1..516952ca959 100644
--- a/.github/workflows/beam_PreCommit_Java.yml
+++ b/.github/workflows/beam_PreCommit_Java.yml
@@ -69,7 +69,7 @@ on:
       - '!sdks/java/io/thrift/**'
       - '!sdks/java/io/tika/**'
 
-  pull_request_target:
+  pull_request:
     branches: ['master', 'release-*']
     paths:
       - 'model/**'
@@ -132,7 +132,7 @@ concurrency:
   group: '${{ github.workflow }} @ ${{ github.event.pull_request.number || 
github.event.pull_request.head.label || github.sha || github.head_ref || 
github.ref }}-${{ github.event.schedule || github.event.comment.id || 
github.event.sender.login }}'
   cancel-in-progress: true
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: write
@@ -165,7 +165,7 @@ jobs:
     timeout-minutes: 180
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event_name == 'workflow_dispatch' ||
       github.event.comment.body == 'Run Java PreCommit'
@@ -204,6 +204,7 @@ jobs:
         with:
           commit: '${{ env.prsha || env.GITHUB_SHA }}'
           comment_mode: ${{ github.event_name == 'issue_comment'  && 'always' 
|| 'off' }}
+          check_run: ${{ github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository }}
           files: '**/build/test-results/**/*.xml'
           large_files: true
       - name: Archive SpotBugs Results
@@ -214,7 +215,7 @@ jobs:
           path: '**/build/reports/spotbugs/*.html'
       - name: Publish SpotBugs Results
         uses: jwgmeligmeyling/[email protected]
-        if: always()
+        if: always() && (github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository)
         with:
           name: Publish SpotBugs
           path: '**/build/reports/spotbugs/*.html'
diff --git a/.github/workflows/beam_PreCommit_Python.yml 
b/.github/workflows/beam_PreCommit_Python.yml
index e897b371b94..a711029e0b1 100644
--- a/.github/workflows/beam_PreCommit_Python.yml
+++ b/.github/workflows/beam_PreCommit_Python.yml
@@ -15,7 +15,7 @@
 
 name: PreCommit Python
 on:
-  pull_request_target:
+  pull_request:
     branches: [ "master", "release-*" ]
     paths: [ "model/**","sdks/python/**","release/**", 
'release/trigger_all_tests.json', 
'.github/trigger_files/beam_PreCommit_Python.json']
   issue_comment:
@@ -28,7 +28,7 @@ on:
     - cron: '0 3/6 * * *'
   workflow_dispatch:
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: write
@@ -86,7 +86,7 @@ jobs:
         python_version: ['3.10','3.14']
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event_name == 'workflow_dispatch' ||
       startsWith(github.event.comment.body, 'Run Python PreCommit')
@@ -150,5 +150,6 @@ jobs:
         with:
           commit: '${{ env.prsha || env.GITHUB_SHA }}'
           comment_mode: ${{ github.event_name == 'issue_comment'  && 'always' 
|| 'off' }}
+          check_run: ${{ github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository }}
           files: '**/pytest*.xml'
           large_files: true
diff --git a/.github/workflows/beam_PreCommit_RAT.yml 
b/.github/workflows/beam_PreCommit_RAT.yml
index 66c17ce082a..443c3fd84f1 100644
--- a/.github/workflows/beam_PreCommit_RAT.yml
+++ b/.github/workflows/beam_PreCommit_RAT.yml
@@ -19,7 +19,7 @@ on:
   push:
     tags: ['v*']
     branches: ['master', 'release-*']
-  pull_request_target:
+  pull_request:
     branches: ['master', 'release-*']
   issue_comment:
     types: [created]
@@ -27,7 +27,7 @@ on:
     - cron: '0 3/6 * * *'
   workflow_dispatch:
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: read
@@ -64,7 +64,7 @@ jobs:
     timeout-minutes: 120
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event_name == 'workflow_dispatch' ||
       github.event.comment.body == 'Run RAT PreCommit'

Reply via email to