This is an automated email from the ASF dual-hosted git repository.
damccorm pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/beam.git
The following commit(s) were added to refs/heads/master by this push:
new 985c8fa0a01 Migrate 7 pilot CI workflows from pull_request_target to
pull_request (#40360)
985c8fa0a01 is described below
commit 985c8fa0a01de9fd4004d269133a388775aafc0b
Author: Danny McCormick <[email protected]>
AuthorDate: Thu Oct 1 14:26:58 2026 +0000
Migrate 7 pilot CI workflows from pull_request_target to pull_request
(#40360)
---
.github/actions/setup-action/action.yml | 2 +-
.github/build.gradle | 4 ++--
.github/workflows/beam_PostCommit_Go.yml | 6 +++---
.github/workflows/beam_PostCommit_Javadoc.yml | 6 +++---
.github/workflows/beam_PreCommit_GHA.yml | 6 +++---
.github/workflows/beam_PreCommit_Go.yml | 6 +++---
.github/workflows/beam_PreCommit_Java.yml | 9 +++++----
.github/workflows/beam_PreCommit_Python.yml | 7 ++++---
.github/workflows/beam_PreCommit_RAT.yml | 6 +++---
9 files changed, 27 insertions(+), 25 deletions(-)
diff --git a/.github/actions/setup-action/action.yml
b/.github/actions/setup-action/action.yml
index 4c4bb275319..4ca21945b12 100644
--- a/.github/actions/setup-action/action.yml
+++ b/.github/actions/setup-action/action.yml
@@ -42,7 +42,7 @@ runs:
PHRASE: "${{ github.event.comment.body }}"
- name: Check out repository code if pull request commit
shell: bash
- if: ${{ github.event_name == 'pull_request_target' }}
+ if: ${{ github.event_name == 'pull_request' || github.event_name ==
'pull_request_target' }}
run: |
# GitHub will automatically generate a merge commit when there are
no merge conflicts.
# We first try to check that out, and fall back to checking out the
tip of the pull request branch.
diff --git a/.github/build.gradle b/.github/build.gradle
index d5a9a6c9dc7..e0243e2f81b 100644
--- a/.github/build.gradle
+++ b/.github/build.gradle
@@ -50,10 +50,10 @@ task check {
if ( fname.startsWith("beam_PreCommit") ||
fname.startsWith("beam_PostCommit") ) {
List paths
try {
- paths = workflow.getAt(true).pull_request_target.paths as List
+ paths = (workflow.getAt(true).pull_request ?:
workflow.getAt(true).pull_request_target).paths as List
} catch (Exception e) {
errors.add("Fail to get the trigger path for ${fname}. " +
- "Make sure it has a pull_request_target trigger.")
+ "Make sure it has a pull_request or pull_request_target
trigger.")
return
}
diff --git a/.github/workflows/beam_PostCommit_Go.yml
b/.github/workflows/beam_PostCommit_Go.yml
index 74c9930816c..7f0afe9d9ee 100644
--- a/.github/workflows/beam_PostCommit_Go.yml
+++ b/.github/workflows/beam_PostCommit_Go.yml
@@ -18,11 +18,11 @@ name: PostCommit Go
on:
schedule:
- cron: '30 3/6 * * *'
- pull_request_target:
+ pull_request:
paths: ['release/trigger_all_tests.json',
'.github/trigger_files/beam_PostCommit_Go.json']
workflow_dispatch:
-#Setting explicit permissions for the action to avoid the default permissions
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
permissions:
actions: write
pull-requests: read
@@ -52,7 +52,7 @@ jobs:
beam_PostCommit_Go:
if: |
github.event_name == 'workflow_dispatch' ||
- github.event_name == 'pull_request_target' ||
+ github.event_name == 'pull_request' ||
(github.event_name == 'schedule' && github.repository == 'apache/beam')
||
github.event.comment.body == 'Run Go PostCommit'
runs-on: [self-hosted, ubuntu-24.04, main]
diff --git a/.github/workflows/beam_PostCommit_Javadoc.yml
b/.github/workflows/beam_PostCommit_Javadoc.yml
index 2ed3777d151..25093813031 100644
--- a/.github/workflows/beam_PostCommit_Javadoc.yml
+++ b/.github/workflows/beam_PostCommit_Javadoc.yml
@@ -20,7 +20,7 @@ name: PostCommit Javadoc
on:
schedule:
- cron: '0 5/6 * * *'
- pull_request_target:
+ pull_request:
paths: ['release/trigger_all_tests.json',
'.github/trigger_files/beam_PostCommit_Javadoc.json']
workflow_dispatch:
@@ -29,7 +29,7 @@ concurrency:
group: '${{ github.workflow }} @ ${{ github.event.pull_request.number ||
github.sha || github.head_ref || github.ref }}-${{ github.event.schedule ||
github.event.comment.id || github.event.sender.login }}'
cancel-in-progress: true
-#Setting explicit permissions for the action to avoid the default permissions
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
permissions:
actions: write
pull-requests: read
@@ -61,7 +61,7 @@ jobs:
job_phrase: [Run Javadoc PostCommit]
if: |
github.event_name == 'workflow_dispatch' ||
- github.event_name == 'pull_request_target' ||
+ github.event_name == 'pull_request' ||
(github.event_name == 'schedule' && github.repository == 'apache/beam')
||
github.event.comment.body == 'Run Javadoc PostCommit'
steps:
diff --git a/.github/workflows/beam_PreCommit_GHA.yml
b/.github/workflows/beam_PreCommit_GHA.yml
index 96fd5426d7c..684d1f4465a 100644
--- a/.github/workflows/beam_PreCommit_GHA.yml
+++ b/.github/workflows/beam_PreCommit_GHA.yml
@@ -20,7 +20,7 @@ on:
tags: ['v*']
branches: ['master', 'release-*']
paths: ['.github/**/*.yml']
- pull_request_target:
+ pull_request:
branches: ['master', 'release-*' ]
paths: ['.github/**/*.yml', 'release/trigger_all_tests.json',
'.github/trigger_files/beam_PreCommit_GHA.json']
issue_comment:
@@ -29,7 +29,7 @@ on:
- cron: '0 */6 * * *'
workflow_dispatch:
-#Setting explicit permissions for the action to avoid the default permissions
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
permissions:
actions: write
pull-requests: read
@@ -66,7 +66,7 @@ jobs:
timeout-minutes: 30
if: |
github.event_name == 'push' ||
- github.event_name == 'pull_request_target' ||
+ github.event_name == 'pull_request' ||
(github.event_name == 'schedule' && github.repository == 'apache/beam')
||
github.event_name == 'workflow_dispatch' ||
github.event.comment.body == 'Run GHA PreCommit'
diff --git a/.github/workflows/beam_PreCommit_Go.yml
b/.github/workflows/beam_PreCommit_Go.yml
index 335d531f743..f992cb9118f 100644
--- a/.github/workflows/beam_PreCommit_Go.yml
+++ b/.github/workflows/beam_PreCommit_Go.yml
@@ -20,7 +20,7 @@ on:
tags: ['v*']
branches: ['master', 'release-*']
paths: ['model/**', 'sdks/go.mod', 'sdks/go.sum', 'sdks/go/**',
'release/**', '.github/workflows/beam_PreCommit_Go.yml']
- pull_request_target:
+ pull_request:
branches: ['master', 'release-*']
paths: ['model/**', 'sdks/go.mod', 'sdks/go.sum', 'sdks/go/**',
'release/**', 'release/trigger_all_tests.json',
'.github/trigger_files/beam_PreCommit_Go.json']
issue_comment:
@@ -29,7 +29,7 @@ on:
- cron: '0 1/6 * * *'
workflow_dispatch:
-#Setting explicit permissions for the action to avoid the default permissions
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
permissions:
actions: write
pull-requests: read
@@ -66,7 +66,7 @@ jobs:
timeout-minutes: 120
if: |
github.event_name == 'push' ||
- github.event_name == 'pull_request_target' ||
+ github.event_name == 'pull_request' ||
(github.event_name == 'schedule' && github.repository == 'apache/beam')
||
github.event_name == 'workflow_dispatch' ||
github.event.comment.body == 'Run Go PreCommit'
diff --git a/.github/workflows/beam_PreCommit_Java.yml
b/.github/workflows/beam_PreCommit_Java.yml
index ddfbec257a1..516952ca959 100644
--- a/.github/workflows/beam_PreCommit_Java.yml
+++ b/.github/workflows/beam_PreCommit_Java.yml
@@ -69,7 +69,7 @@ on:
- '!sdks/java/io/thrift/**'
- '!sdks/java/io/tika/**'
- pull_request_target:
+ pull_request:
branches: ['master', 'release-*']
paths:
- 'model/**'
@@ -132,7 +132,7 @@ concurrency:
group: '${{ github.workflow }} @ ${{ github.event.pull_request.number ||
github.event.pull_request.head.label || github.sha || github.head_ref ||
github.ref }}-${{ github.event.schedule || github.event.comment.id ||
github.event.sender.login }}'
cancel-in-progress: true
-#Setting explicit permissions for the action to avoid the default permissions
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
permissions:
actions: write
pull-requests: write
@@ -165,7 +165,7 @@ jobs:
timeout-minutes: 180
if: |
github.event_name == 'push' ||
- github.event_name == 'pull_request_target' ||
+ github.event_name == 'pull_request' ||
(github.event_name == 'schedule' && github.repository == 'apache/beam')
||
github.event_name == 'workflow_dispatch' ||
github.event.comment.body == 'Run Java PreCommit'
@@ -204,6 +204,7 @@ jobs:
with:
commit: '${{ env.prsha || env.GITHUB_SHA }}'
comment_mode: ${{ github.event_name == 'issue_comment' && 'always'
|| 'off' }}
+ check_run: ${{ github.event_name != 'pull_request' ||
github.event.pull_request.head.repo.full_name == github.repository }}
files: '**/build/test-results/**/*.xml'
large_files: true
- name: Archive SpotBugs Results
@@ -214,7 +215,7 @@ jobs:
path: '**/build/reports/spotbugs/*.html'
- name: Publish SpotBugs Results
uses: jwgmeligmeyling/[email protected]
- if: always()
+ if: always() && (github.event_name != 'pull_request' ||
github.event.pull_request.head.repo.full_name == github.repository)
with:
name: Publish SpotBugs
path: '**/build/reports/spotbugs/*.html'
diff --git a/.github/workflows/beam_PreCommit_Python.yml
b/.github/workflows/beam_PreCommit_Python.yml
index e897b371b94..a711029e0b1 100644
--- a/.github/workflows/beam_PreCommit_Python.yml
+++ b/.github/workflows/beam_PreCommit_Python.yml
@@ -15,7 +15,7 @@
name: PreCommit Python
on:
- pull_request_target:
+ pull_request:
branches: [ "master", "release-*" ]
paths: [ "model/**","sdks/python/**","release/**",
'release/trigger_all_tests.json',
'.github/trigger_files/beam_PreCommit_Python.json']
issue_comment:
@@ -28,7 +28,7 @@ on:
- cron: '0 3/6 * * *'
workflow_dispatch:
-#Setting explicit permissions for the action to avoid the default permissions
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
permissions:
actions: write
pull-requests: write
@@ -86,7 +86,7 @@ jobs:
python_version: ['3.10','3.14']
if: |
github.event_name == 'push' ||
- github.event_name == 'pull_request_target' ||
+ github.event_name == 'pull_request' ||
(github.event_name == 'schedule' && github.repository == 'apache/beam')
||
github.event_name == 'workflow_dispatch' ||
startsWith(github.event.comment.body, 'Run Python PreCommit')
@@ -150,5 +150,6 @@ jobs:
with:
commit: '${{ env.prsha || env.GITHUB_SHA }}'
comment_mode: ${{ github.event_name == 'issue_comment' && 'always'
|| 'off' }}
+ check_run: ${{ github.event_name != 'pull_request' ||
github.event.pull_request.head.repo.full_name == github.repository }}
files: '**/pytest*.xml'
large_files: true
diff --git a/.github/workflows/beam_PreCommit_RAT.yml
b/.github/workflows/beam_PreCommit_RAT.yml
index 66c17ce082a..443c3fd84f1 100644
--- a/.github/workflows/beam_PreCommit_RAT.yml
+++ b/.github/workflows/beam_PreCommit_RAT.yml
@@ -19,7 +19,7 @@ on:
push:
tags: ['v*']
branches: ['master', 'release-*']
- pull_request_target:
+ pull_request:
branches: ['master', 'release-*']
issue_comment:
types: [created]
@@ -27,7 +27,7 @@ on:
- cron: '0 3/6 * * *'
workflow_dispatch:
-#Setting explicit permissions for the action to avoid the default permissions
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
permissions:
actions: write
pull-requests: read
@@ -64,7 +64,7 @@ jobs:
timeout-minutes: 120
if: |
github.event_name == 'push' ||
- github.event_name == 'pull_request_target' ||
+ github.event_name == 'pull_request' ||
(github.event_name == 'schedule' && github.repository == 'apache/beam')
||
github.event_name == 'workflow_dispatch' ||
github.event.comment.body == 'Run RAT PreCommit'