This is an automated email from the ASF dual-hosted git repository.

damccorm pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/beam.git


The following commit(s) were added to refs/heads/master by this push:
     new adc62a984fd Migrate PreCommit workflows from pull_request_target to 
pull_request (#40372)
adc62a984fd is described below

commit adc62a984fd3fe3ce81b83739ea62970d9341297
Author: Danny McCormick <[email protected]>
AuthorDate: Thu Oct 1 17:33:46 2026 +0000

    Migrate PreCommit workflows from pull_request_target to pull_request 
(#40372)
---
 .github/workflows/IO_Iceberg_Unit_Tests.yml                      | 9 +++++----
 .github/workflows/beam_Playground_Precommit.yml                  | 4 ++--
 .github/workflows/beam_PreCommit_CommunityMetrics.yml            | 6 +++---
 .github/workflows/beam_PreCommit_GoPortable.yml                  | 6 +++---
 .github/workflows/beam_PreCommit_GoPrism.yml                     | 6 +++---
 .github/workflows/beam_PreCommit_ItFramework.yml                 | 7 ++++---
 .../beam_PreCommit_Java_Amazon-Web-Services2_IO_Direct.yml       | 9 +++++----
 .github/workflows/beam_PreCommit_Java_Amqp_IO_Direct.yml         | 9 +++++----
 .github/workflows/beam_PreCommit_Java_Azure_IO_Direct.yml        | 9 +++++----
 .github/workflows/beam_PreCommit_Java_Cassandra_IO_Direct.yml    | 9 +++++----
 .github/workflows/beam_PreCommit_Java_Cdap_IO_Direct.yml         | 9 +++++----
 .github/workflows/beam_PreCommit_Java_Clickhouse_IO_Direct.yml   | 9 +++++----
 .github/workflows/beam_PreCommit_Java_Csv_IO_Direct.yml          | 9 +++++----
 .github/workflows/beam_PreCommit_Java_Datadog_IO_Direct.yml      | 9 +++++----
 .github/workflows/beam_PreCommit_Java_Dataflow.yml               | 7 ++++---
 .github/workflows/beam_PreCommit_Java_Debezium_IO_Direct.yml     | 9 +++++----
 .github/workflows/beam_PreCommit_Java_Delta_IO_Direct.yml        | 9 +++++----
 .../workflows/beam_PreCommit_Java_ElasticSearch_IO_Direct.yml    | 9 +++++----
 .github/workflows/beam_PreCommit_Java_Examples_Dataflow.yml      | 7 ++++---
 .../workflows/beam_PreCommit_Java_Examples_Dataflow_Java11.yml   | 7 ++++---
 .../beam_PreCommit_Java_File-schema-transform_IO_Direct.yml      | 9 +++++----
 .github/workflows/beam_PreCommit_Java_Flink_Versions.yml         | 5 +++--
 .github/workflows/beam_PreCommit_Java_GCP_IO_Direct.yml          | 7 ++++---
 .github/workflows/beam_PreCommit_Java_Google-ads_IO_Direct.yml   | 9 +++++----
 .github/workflows/beam_PreCommit_Java_HBase_IO_Direct.yml        | 9 +++++----
 .github/workflows/beam_PreCommit_Java_HCatalog_IO_Direct.yml     | 9 +++++----
 .github/workflows/beam_PreCommit_Java_Hadoop_IO_Direct.yml       | 9 +++++----
 .github/workflows/beam_PreCommit_Java_IOs_Direct.yml             | 9 +++++----
 .github/workflows/beam_PreCommit_Java_InfluxDb_IO_Direct.yml     | 9 +++++----
 .github/workflows/beam_PreCommit_Java_JDBC_IO_Direct.yml         | 9 +++++----
 .github/workflows/beam_PreCommit_Java_Jms_IO_Direct.yml          | 9 +++++----
 .github/workflows/beam_PreCommit_Java_Kafka_IO_Direct.yml        | 9 +++++----
 .github/workflows/beam_PreCommit_Java_Kafka_Streams_Runner.yml   | 9 +++++----
 .github/workflows/beam_PreCommit_Java_Kudu_IO_Direct.yml         | 9 +++++----
 .github/workflows/beam_PreCommit_Java_MongoDb_IO_Direct.yml      | 9 +++++----
 .github/workflows/beam_PreCommit_Java_Mqtt_IO_Direct.yml         | 9 +++++----
 .github/workflows/beam_PreCommit_Java_Neo4j_IO_Direct.yml        | 9 +++++----
 .github/workflows/beam_PreCommit_Java_PVR_Flink_Batch.yml        | 6 +++---
 .github/workflows/beam_PreCommit_Java_PVR_Flink_Docker.yml       | 7 ++++---
 .github/workflows/beam_PreCommit_Java_PVR_Prism_Loopback.yml     | 6 +++---
 .github/workflows/beam_PreCommit_Java_Parquet_IO_Direct.yml      | 9 +++++----
 .github/workflows/beam_PreCommit_Java_Pulsar_IO_Direct.yml       | 9 +++++----
 .github/workflows/beam_PreCommit_Java_RabbitMq_IO_Direct.yml     | 9 +++++----
 .github/workflows/beam_PreCommit_Java_Redis_IO_Direct.yml        | 9 +++++----
 .../workflows/beam_PreCommit_Java_RequestResponse_IO_Direct.yml  | 9 +++++----
 .github/workflows/beam_PreCommit_Java_SingleStore_IO_Direct.yml  | 9 +++++----
 .github/workflows/beam_PreCommit_Java_Snowflake_IO_Direct.yml    | 9 +++++----
 .github/workflows/beam_PreCommit_Java_Solace_IO_Direct.yml       | 9 +++++----
 .github/workflows/beam_PreCommit_Java_Solr_IO_Direct.yml         | 9 +++++----
 .github/workflows/beam_PreCommit_Java_Spark_Versions.yml         | 7 ++++---
 .github/workflows/beam_PreCommit_Java_Splunk_IO_Direct.yml       | 9 +++++----
 .github/workflows/beam_PreCommit_Java_Thrift_IO_Direct.yml       | 9 +++++----
 .github/workflows/beam_PreCommit_Java_Tika_IO_Direct.yml         | 9 +++++----
 .github/workflows/beam_PreCommit_Kotlin_Examples.yml             | 6 +++---
 .github/workflows/beam_PreCommit_Portable_Python.yml             | 6 +++---
 .github/workflows/beam_PreCommit_Prism_Python.yml                | 6 +++---
 .github/workflows/beam_PreCommit_PythonDocker.yml                | 6 +++---
 .github/workflows/beam_PreCommit_PythonDocs.yml                  | 6 +++---
 .github/workflows/beam_PreCommit_PythonFormatter.yml             | 6 +++---
 .github/workflows/beam_PreCommit_PythonLint.yml                  | 6 +++---
 .github/workflows/beam_PreCommit_Python_Dataframes.yml           | 7 ++++---
 .github/workflows/beam_PreCommit_Python_Dill.yml                 | 6 +++---
 .github/workflows/beam_PreCommit_Python_Integration.yml          | 7 ++++---
 .github/workflows/beam_PreCommit_Python_PVR_Flink.yml            | 7 ++++---
 .github/workflows/beam_PreCommit_Python_Runners.yml              | 7 ++++---
 .github/workflows/beam_PreCommit_SQL.yml                         | 9 +++++----
 .github/workflows/beam_PreCommit_SQL_Java17.yml                  | 9 +++++----
 .github/workflows/beam_PreCommit_Spotless.yml                    | 6 +++---
 .github/workflows/beam_PreCommit_Typescript.yml                  | 6 +++---
 .github/workflows/beam_PreCommit_Website.yml                     | 6 +++---
 .github/workflows/beam_PreCommit_Whitespace.yml                  | 4 ++--
 .github/workflows/beam_PreCommit_Xlang_Generated_Transforms.yml  | 6 +++---
 .github/workflows/beam_PreCommit_Yaml_Xlang_Direct.yml           | 7 ++++---
 73 files changed, 311 insertions(+), 257 deletions(-)

diff --git a/.github/workflows/IO_Iceberg_Unit_Tests.yml 
b/.github/workflows/IO_Iceberg_Unit_Tests.yml
index f3fd63a9d47..9dc43c5e002 100644
--- a/.github/workflows/IO_Iceberg_Unit_Tests.yml
+++ b/.github/workflows/IO_Iceberg_Unit_Tests.yml
@@ -25,7 +25,7 @@ on:
       - "sdks/java/expansion-service/**"
       - "sdks/java/io/expansion-service/**"
       - ".github/workflows/IO_Iceberg_Unit_Tests.yml"
-  pull_request_target:
+  pull_request:
     branches: ['master', 'release-*']
     paths:
       - "sdks/java/io/iceberg/**"
@@ -40,7 +40,7 @@ on:
     - cron: '15 1/6 * * *'
   workflow_dispatch:
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: write
@@ -76,7 +76,7 @@ jobs:
     timeout-minutes: 60
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event_name == 'workflow_dispatch' ||
       github.event.comment.body == 'Run IcebergIO Unit Tests'
@@ -113,6 +113,7 @@ jobs:
         with:
           commit: '${{ env.prsha || env.GITHUB_SHA }}'
           comment_mode: ${{ github.event_name == 'issue_comment'  && 'always' 
|| 'off' }}
+          check_run: ${{ github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository }}
           files: '**/build/test-results/**/*.xml'
           large_files: true
       - name: Archive SpotBugs Results
@@ -123,7 +124,7 @@ jobs:
           path: '**/build/reports/spotbugs/*.html'
       - name: Publish SpotBugs Results
         uses: jwgmeligmeyling/[email protected]
-        if: always()
+        if: always() && (github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository)
         with:
           name: Publish SpotBugs
           path: '**/build/reports/spotbugs/*.html'
diff --git a/.github/workflows/beam_Playground_Precommit.yml 
b/.github/workflows/beam_Playground_Precommit.yml
index 589cba36787..c7c2aaefe0e 100644
--- a/.github/workflows/beam_Playground_Precommit.yml
+++ b/.github/workflows/beam_Playground_Precommit.yml
@@ -17,7 +17,7 @@ name: Playground PreCommit
 
 on:
   workflow_dispatch:
-  pull_request_target:
+  pull_request:
     paths:
       - .github/workflows/beam_Playground_Precommit.yml
       - playground/backend/**
@@ -33,7 +33,7 @@ jobs:
   beam_Playground_PreCommit:
     if: |
       github.event_name == 'workflow_dispatch' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event.comment.body == 'Run Playground PreCommit'
     name: ${{ matrix.job_name }} (${{ matrix.job_phrase }})
diff --git a/.github/workflows/beam_PreCommit_CommunityMetrics.yml 
b/.github/workflows/beam_PreCommit_CommunityMetrics.yml
index 63f05bc053a..a37e3c454d6 100644
--- a/.github/workflows/beam_PreCommit_CommunityMetrics.yml
+++ b/.github/workflows/beam_PreCommit_CommunityMetrics.yml
@@ -20,7 +20,7 @@ on:
     tags: ['v*']
     branches: ['master', 'release-*']
     paths: ['.test-infra/metrics/**', 'buildSrc/build.gradle.kts', 
'.github/workflows/beam_PreCommit_CommunityMetrics.yml']
-  pull_request_target:
+  pull_request:
     branches: ['master', 'release-*']
     paths: ['.test-infra/metrics/**', 'buildSrc/build.gradle.kts', 
'release/trigger_all_tests.json', 
'.github/trigger_files/beam_PreCommit_CommunityMetrics.json']
   issue_comment:
@@ -29,7 +29,7 @@ on:
     - cron: '0 1/6 * * *'
   workflow_dispatch:
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: read
@@ -66,7 +66,7 @@ jobs:
         job_phrase: [Run CommunityMetrics PreCommit]
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event_name == 'workflow_dispatch' ||
       github.event.comment.body == 'Run CommunityMetrics PreCommit'
diff --git a/.github/workflows/beam_PreCommit_GoPortable.yml 
b/.github/workflows/beam_PreCommit_GoPortable.yml
index 4239555c038..2e0fe2c8f30 100644
--- a/.github/workflows/beam_PreCommit_GoPortable.yml
+++ b/.github/workflows/beam_PreCommit_GoPortable.yml
@@ -20,7 +20,7 @@ on:
     tags: ['v*']
     branches: ['master', 'release-*']
     paths: ['model/**', 'sdks/go.mod', 'sdks/go.sum', 'sdks/go/**', 
'release/**', '.github/workflows/beam_PreCommit_GoPortable.yml']
-  pull_request_target:
+  pull_request:
     branches: ['master', 'release-*']
     paths: ['model/**', 'sdks/go.mod', 'sdks/go.sum', 'sdks/go/**', 
'release/**', 'release/trigger_all_tests.json', 
'.github/trigger_files/beam_PreCommit_GoPortable.json']
   issue_comment:
@@ -41,7 +41,7 @@ env:
   # TODO(https://github.com/grpc/grpc/issues/37710): Remove once fixed.
   GRPC_ENABLE_FORK_SUPPORT: '0'
 
-# Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: read
@@ -68,7 +68,7 @@ jobs:
     timeout-minutes: 120
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event_name == 'workflow_dispatch' ||
       github.event.comment.body == 'Run GoPortable PreCommit'
diff --git a/.github/workflows/beam_PreCommit_GoPrism.yml 
b/.github/workflows/beam_PreCommit_GoPrism.yml
index cac49331592..2dc6c7526b4 100644
--- a/.github/workflows/beam_PreCommit_GoPrism.yml
+++ b/.github/workflows/beam_PreCommit_GoPrism.yml
@@ -20,7 +20,7 @@ on:
     tags: ['v*']
     branches: ['master', 'release-*']
     paths: ['model/**', 'sdks/go.mod', 'sdks/go.sum', 'sdks/go/**', 
'release/**', '.github/workflows/beam_PreCommit_GoPrism.yml']
-  pull_request_target:
+  pull_request:
     branches: ['master', 'release-*']
     paths: ['model/**', 'sdks/go.mod', 'sdks/go.sum', 'sdks/go/**', 
'release/**', 'release/trigger_all_tests.json', 
'.github/trigger_files/beam_PreCommit_GoPrism.json']
   issue_comment:
@@ -39,7 +39,7 @@ env:
   GRADLE_ENTERPRISE_CACHE_USERNAME: ${{ secrets.GE_CACHE_USERNAME }}
   GRADLE_ENTERPRISE_CACHE_PASSWORD: ${{ secrets.GE_CACHE_PASSWORD }}
 
-# Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: read
@@ -66,7 +66,7 @@ jobs:
     timeout-minutes: 120
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event_name == 'workflow_dispatch' ||
       github.event.comment.body == 'Run GoPrism PreCommit'
diff --git a/.github/workflows/beam_PreCommit_ItFramework.yml 
b/.github/workflows/beam_PreCommit_ItFramework.yml
index c0b666a6123..5c9fc71c744 100644
--- a/.github/workflows/beam_PreCommit_ItFramework.yml
+++ b/.github/workflows/beam_PreCommit_ItFramework.yml
@@ -24,7 +24,7 @@ on:
     paths:
       - 'it/**'
       - '.github/workflows/beam_PreCommit_ItFramework.yml'
-  pull_request_target:
+  pull_request:
     branches: ['master', 'release-*']
     paths:
       - 'it/**'
@@ -46,7 +46,7 @@ env:
   GRADLE_ENTERPRISE_CACHE_USERNAME: ${{ secrets.GE_CACHE_USERNAME }}
   GRADLE_ENTERPRISE_CACHE_PASSWORD: ${{ secrets.GE_CACHE_PASSWORD }}
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: write
@@ -71,7 +71,7 @@ jobs:
         job_phrase: [Run It_Framework PreCommit]
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event_name == 'workflow_dispatch' ||
       github.event.comment.body == 'Run It_Framework PreCommit'
@@ -103,5 +103,6 @@ jobs:
         with:
           commit: '${{ env.prsha || env.GITHUB_SHA }}'
           comment_mode: ${{ github.event_name == 'issue_comment'  && 'always' 
|| 'off' }}
+          check_run: ${{ github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository }}
           files: '**/build/test-results/**/*.xml'
           large_files: true
diff --git 
a/.github/workflows/beam_PreCommit_Java_Amazon-Web-Services2_IO_Direct.yml 
b/.github/workflows/beam_PreCommit_Java_Amazon-Web-Services2_IO_Direct.yml
index 9e9e33ef288..b71d8a00c2b 100644
--- a/.github/workflows/beam_PreCommit_Java_Amazon-Web-Services2_IO_Direct.yml
+++ b/.github/workflows/beam_PreCommit_Java_Amazon-Web-Services2_IO_Direct.yml
@@ -31,7 +31,7 @@ on:
       - "gradle.bat"
       - "settings.gradle.kts"
       - 
".github/workflows/beam_PreCommit_Java_Amazon-Web-Services2_IO_Direct.yml"
-  pull_request_target:
+  pull_request:
     branches: ['master', 'release-*']
     paths:
       - "sdks/java/io/amazon-web-services2/**"
@@ -52,7 +52,7 @@ on:
     - cron: '0 1/6 * * *'
   workflow_dispatch:
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: write
@@ -88,7 +88,7 @@ jobs:
     timeout-minutes: 60
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event_name == 'workflow_dispatch' ||
       github.event.comment.body == 'Run Java_Amazon-Web-Services2_IO_Direct 
PreCommit'
@@ -131,6 +131,7 @@ jobs:
         with:
           commit: '${{ env.prsha || env.GITHUB_SHA }}'
           comment_mode: ${{ github.event_name == 'issue_comment'  && 'always' 
|| 'off' }}
+          check_run: ${{ github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository }}
           files: '**/build/test-results/**/*.xml'
           large_files: true
       - name: Archive SpotBugs Results
@@ -141,7 +142,7 @@ jobs:
           path: '**/build/reports/spotbugs/*.html'
       - name: Publish SpotBugs Results
         uses: jwgmeligmeyling/[email protected]
-        if: always()
+        if: always() && (github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository)
         with:
           name: Publish SpotBugs
           path: '**/build/reports/spotbugs/*.html'
diff --git a/.github/workflows/beam_PreCommit_Java_Amqp_IO_Direct.yml 
b/.github/workflows/beam_PreCommit_Java_Amqp_IO_Direct.yml
index aed74b85e7b..85d264ce54a 100644
--- a/.github/workflows/beam_PreCommit_Java_Amqp_IO_Direct.yml
+++ b/.github/workflows/beam_PreCommit_Java_Amqp_IO_Direct.yml
@@ -22,7 +22,7 @@ on:
     paths:
       - "sdks/java/io/amqp/**"
       - ".github/workflows/beam_PreCommit_Java_Amqp_IO_Direct.yml"
-  pull_request_target:
+  pull_request:
     branches: ['master', 'release-*']
     paths:
       - "sdks/java/io/amqp/**"
@@ -34,7 +34,7 @@ on:
     - cron: '15 1/6 * * *'
   workflow_dispatch:
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: write
@@ -70,7 +70,7 @@ jobs:
     timeout-minutes: 60
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event_name == 'workflow_dispatch' ||
       github.event.comment.body == 'Run Java_Amqp_IO_Direct PreCommit'
@@ -106,6 +106,7 @@ jobs:
         with:
           commit: '${{ env.prsha || env.GITHUB_SHA }}'
           comment_mode: ${{ github.event_name == 'issue_comment'  && 'always' 
|| 'off' }}
+          check_run: ${{ github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository }}
           files: '**/build/test-results/**/*.xml'
       - name: Archive SpotBugs Results
         uses: actions/upload-artifact@v7
@@ -115,7 +116,7 @@ jobs:
           path: '**/build/reports/spotbugs/*.html'
       - name: Publish SpotBugs Results
         uses: jwgmeligmeyling/[email protected]
-        if: always()
+        if: always() && (github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository)
         with:
           name: Publish SpotBugs
           path: '**/build/reports/spotbugs/*.html'
diff --git a/.github/workflows/beam_PreCommit_Java_Azure_IO_Direct.yml 
b/.github/workflows/beam_PreCommit_Java_Azure_IO_Direct.yml
index 5f7d89c5ea3..0b18bcbc8a2 100644
--- a/.github/workflows/beam_PreCommit_Java_Azure_IO_Direct.yml
+++ b/.github/workflows/beam_PreCommit_Java_Azure_IO_Direct.yml
@@ -31,7 +31,7 @@ on:
       - "gradle.bat"
       - "settings.gradle.kts"
       - ".github/workflows/beam_PreCommit_Java_Azure_IO_Direct.yml"
-  pull_request_target:
+  pull_request:
     branches: ['master', 'release-*']
     paths:
       - "sdks/java/io/azure/**"
@@ -52,7 +52,7 @@ on:
     - cron: '15 1/6 * * *'
   workflow_dispatch:
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: write
@@ -88,7 +88,7 @@ jobs:
     timeout-minutes: 60
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event_name == 'workflow_dispatch' ||
       github.event.comment.body == 'Run Java_Azure_IO_Direct PreCommit'
@@ -124,6 +124,7 @@ jobs:
         with:
           commit: '${{ env.prsha || env.GITHUB_SHA }}'
           comment_mode: ${{ github.event_name == 'issue_comment'  && 'always' 
|| 'off' }}
+          check_run: ${{ github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository }}
           files: '**/build/test-results/**/*.xml'
           large_files: true
       - name: Archive SpotBugs Results
@@ -134,7 +135,7 @@ jobs:
           path: '**/build/reports/spotbugs/*.html'
       - name: Publish SpotBugs Results
         uses: jwgmeligmeyling/[email protected]
-        if: always()
+        if: always() && (github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository)
         with:
           name: Publish SpotBugs
           path: '**/build/reports/spotbugs/*.html'
diff --git a/.github/workflows/beam_PreCommit_Java_Cassandra_IO_Direct.yml 
b/.github/workflows/beam_PreCommit_Java_Cassandra_IO_Direct.yml
index 8e2f4041c15..4a1d331e71c 100644
--- a/.github/workflows/beam_PreCommit_Java_Cassandra_IO_Direct.yml
+++ b/.github/workflows/beam_PreCommit_Java_Cassandra_IO_Direct.yml
@@ -22,7 +22,7 @@ on:
     paths:
       - "sdks/java/io/cassandra/**"
       - ".github/workflows/beam_PreCommit_Java_Cassandra_IO_Direct.yml"
-  pull_request_target:
+  pull_request:
     branches: ['master', 'release-*']
     paths:
       - "sdks/java/io/cassandra/**"
@@ -34,7 +34,7 @@ on:
     - cron: '15 1/6 * * *'
   workflow_dispatch:
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: write
@@ -70,7 +70,7 @@ jobs:
     timeout-minutes: 60
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event_name == 'workflow_dispatch' ||
       github.event.comment.body == 'Run Java_Cassandra_IO_Direct PreCommit'
@@ -108,6 +108,7 @@ jobs:
         with:
           commit: '${{ env.prsha || env.GITHUB_SHA }}'
           comment_mode: ${{ github.event_name == 'issue_comment'  && 'always' 
|| 'off' }}
+          check_run: ${{ github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository }}
           files: '**/build/test-results/**/*.xml'
           large_files: true
       - name: Archive SpotBugs Results
@@ -118,7 +119,7 @@ jobs:
           path: '**/build/reports/spotbugs/*.html'
       - name: Publish SpotBugs Results
         uses: jwgmeligmeyling/[email protected]
-        if: always()
+        if: always() && (github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository)
         with:
           name: Publish SpotBugs
           path: '**/build/reports/spotbugs/*.html'
diff --git a/.github/workflows/beam_PreCommit_Java_Cdap_IO_Direct.yml 
b/.github/workflows/beam_PreCommit_Java_Cdap_IO_Direct.yml
index 8118273ed62..8d2931bf62e 100644
--- a/.github/workflows/beam_PreCommit_Java_Cdap_IO_Direct.yml
+++ b/.github/workflows/beam_PreCommit_Java_Cdap_IO_Direct.yml
@@ -24,7 +24,7 @@ on:
       - "sdks/java/io/hadoop-common/**"
       - "sdks/java/io/hadoop-format/**"
       - ".github/workflows/beam_PreCommit_Java_Cdap_IO_Direct.yml"
-  pull_request_target:
+  pull_request:
     branches: ['master', 'release-*']
     paths:
       - "sdks/java/io/cdap/**"
@@ -38,7 +38,7 @@ on:
     - cron: '15 1/6 * * *'
   workflow_dispatch:
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: write
@@ -74,7 +74,7 @@ jobs:
     timeout-minutes: 60
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event_name == 'workflow_dispatch' ||
       github.event.comment.body == 'Run Java_Cdap_IO_Direct PreCommit'
@@ -110,6 +110,7 @@ jobs:
         with:
           commit: '${{ env.prsha || env.GITHUB_SHA }}'
           comment_mode: ${{ github.event_name == 'issue_comment'  && 'always' 
|| 'off' }}
+          check_run: ${{ github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository }}
           files: '**/build/test-results/**/*.xml'
           large_files: true
       - name: Archive SpotBugs Results
@@ -120,7 +121,7 @@ jobs:
           path: '**/build/reports/spotbugs/*.html'
       - name: Publish SpotBugs Results
         uses: jwgmeligmeyling/[email protected]
-        if: always()
+        if: always() && (github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository)
         with:
           name: Publish SpotBugs
           path: '**/build/reports/spotbugs/*.html'
diff --git a/.github/workflows/beam_PreCommit_Java_Clickhouse_IO_Direct.yml 
b/.github/workflows/beam_PreCommit_Java_Clickhouse_IO_Direct.yml
index 35c1ec4aeeb..a2def1eaa88 100644
--- a/.github/workflows/beam_PreCommit_Java_Clickhouse_IO_Direct.yml
+++ b/.github/workflows/beam_PreCommit_Java_Clickhouse_IO_Direct.yml
@@ -22,7 +22,7 @@ on:
     paths:
       - "sdks/java/io/clickhouse/**"
       - ".github/workflows/beam_PreCommit_Java_Clickhouse_IO_Direct.yml"
-  pull_request_target:
+  pull_request:
     branches: ['master', 'release-*']
     paths:
       - "sdks/java/io/clickhouse/**"
@@ -34,7 +34,7 @@ on:
     - cron: '15 1/6 * * *'
   workflow_dispatch:
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: write
@@ -70,7 +70,7 @@ jobs:
     timeout-minutes: 60
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event_name == 'workflow_dispatch' ||
       github.event.comment.body == 'Run Java_Clickhouse_IO_Direct PreCommit'
@@ -113,6 +113,7 @@ jobs:
         with:
           commit: '${{ env.prsha || env.GITHUB_SHA }}'
           comment_mode: ${{ github.event_name == 'issue_comment'  && 'always' 
|| 'off' }}
+          check_run: ${{ github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository }}
           files: '**/build/test-results/**/*.xml'
           large_files: true
       - name: Archive SpotBugs Results
@@ -123,7 +124,7 @@ jobs:
           path: '**/build/reports/spotbugs/*.html'
       - name: Publish SpotBugs Results
         uses: jwgmeligmeyling/[email protected]
-        if: always()
+        if: always() && (github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository)
         with:
           name: Publish SpotBugs
           path: '**/build/reports/spotbugs/*.html'
diff --git a/.github/workflows/beam_PreCommit_Java_Csv_IO_Direct.yml 
b/.github/workflows/beam_PreCommit_Java_Csv_IO_Direct.yml
index 4d4a7231760..2f67c897618 100644
--- a/.github/workflows/beam_PreCommit_Java_Csv_IO_Direct.yml
+++ b/.github/workflows/beam_PreCommit_Java_Csv_IO_Direct.yml
@@ -22,7 +22,7 @@ on:
     paths:
       - "sdks/java/io/csv/**"
       - ".github/workflows/beam_PreCommit_Java_Csv_IO_Direct.yml"
-  pull_request_target:
+  pull_request:
     branches: ['master', 'release-*']
     paths:
       - "sdks/java/io/csv/**"
@@ -34,7 +34,7 @@ on:
     - cron: '15 1/6 * * *'
   workflow_dispatch:
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: write
@@ -70,7 +70,7 @@ jobs:
     timeout-minutes: 60
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event_name == 'workflow_dispatch' ||
       github.event.comment.body == 'Run Java_Csv_IO_Direct PreCommit'
@@ -106,6 +106,7 @@ jobs:
         with:
           commit: '${{ env.prsha || env.GITHUB_SHA }}'
           comment_mode: ${{ github.event_name == 'issue_comment'  && 'always' 
|| 'off' }}
+          check_run: ${{ github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository }}
           files: '**/build/test-results/**/*.xml'
           large_files: true
       - name: Archive SpotBugs Results
@@ -116,7 +117,7 @@ jobs:
           path: '**/build/reports/spotbugs/*.html'
       - name: Publish SpotBugs Results
         uses: jwgmeligmeyling/[email protected]
-        if: always()
+        if: always() && (github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository)
         with:
           name: Publish SpotBugs
           path: '**/build/reports/spotbugs/*.html'
diff --git a/.github/workflows/beam_PreCommit_Java_Datadog_IO_Direct.yml 
b/.github/workflows/beam_PreCommit_Java_Datadog_IO_Direct.yml
index 57233c8a0d6..83eb1260c0d 100644
--- a/.github/workflows/beam_PreCommit_Java_Datadog_IO_Direct.yml
+++ b/.github/workflows/beam_PreCommit_Java_Datadog_IO_Direct.yml
@@ -22,7 +22,7 @@ on:
     paths:
       - "sdks/java/io/datadog/**"
       - ".github/workflows/beam_PreCommit_Java_Datadog_IO_Direct.yml"
-  pull_request_target:
+  pull_request:
     branches: ['master', 'release-*']
     paths:
       - "sdks/java/io/datadog/**"
@@ -34,7 +34,7 @@ on:
     - cron: '15 1/6 * * *'
   workflow_dispatch:
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: write
@@ -70,7 +70,7 @@ jobs:
     timeout-minutes: 60
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event_name == 'workflow_dispatch' ||
       github.event.comment.body == 'Run Java_Datadog_IO_Direct PreCommit'
@@ -106,6 +106,7 @@ jobs:
         with:
           commit: '${{ env.prsha || env.GITHUB_SHA }}'
           comment_mode: ${{ github.event_name == 'issue_comment'  && 'always' 
|| 'off' }}
+          check_run: ${{ github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository }}
           files: '**/build/test-results/**/*.xml'
           large_files: true
       - name: Archive SpotBugs Results
@@ -116,7 +117,7 @@ jobs:
           path: '**/build/reports/spotbugs/*.html'
       - name: Publish SpotBugs Results
         uses: jwgmeligmeyling/[email protected]
-        if: always()
+        if: always() && (github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository)
         with:
           name: Publish SpotBugs
           path: '**/build/reports/spotbugs/*.html'
diff --git a/.github/workflows/beam_PreCommit_Java_Dataflow.yml 
b/.github/workflows/beam_PreCommit_Java_Dataflow.yml
index b7693492393..47b83e2c8b8 100644
--- a/.github/workflows/beam_PreCommit_Java_Dataflow.yml
+++ b/.github/workflows/beam_PreCommit_Java_Dataflow.yml
@@ -23,7 +23,7 @@ on:
     paths:
       - 'runners/google-cloud-dataflow-java/worker/**'
       - '.github/workflows/beam_PreCommit_Java_Dataflow.yml'
-  pull_request_target:
+  pull_request:
     branches: ['master', 'release-*']
     paths:
       - 'runners/google-cloud-dataflow-java/worker/**'
@@ -72,7 +72,7 @@ jobs:
     timeout-minutes: 240
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event_name == 'workflow_dispatch' ||
       github.event.comment.body == 'Run Java Dataflow Non-portable Worker 
PreCommit'
@@ -111,6 +111,7 @@ jobs:
         with:
           commit: '${{ env.prsha || env.GITHUB_SHA }}'
           comment_mode: ${{ github.event_name == 'issue_comment'  && 'always' 
|| 'off' }}
+          check_run: ${{ github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository }}
           files: '**/build/test-results/**/*.xml'
           large_files: true
       - name: Archive SpotBugs Results
@@ -121,7 +122,7 @@ jobs:
           path: '**/build/reports/spotbugs/*.html'
       - name: Publish SpotBugs Results
         uses: jwgmeligmeyling/[email protected]
-        if: always()
+        if: always() && (github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository)
         with:
           name: Publish SpotBugs
           path: '**/build/reports/spotbugs/*.html'
diff --git a/.github/workflows/beam_PreCommit_Java_Debezium_IO_Direct.yml 
b/.github/workflows/beam_PreCommit_Java_Debezium_IO_Direct.yml
index 8b22c8405f3..b32078641cb 100644
--- a/.github/workflows/beam_PreCommit_Java_Debezium_IO_Direct.yml
+++ b/.github/workflows/beam_PreCommit_Java_Debezium_IO_Direct.yml
@@ -22,7 +22,7 @@ on:
     paths:
       - "sdks/java/io/debezium/**"
       - ".github/workflows/beam_PreCommit_Java_Debezium_IO_Direct.yml"
-  pull_request_target:
+  pull_request:
     branches: ['master', 'release-*']
     paths:
       - "sdks/java/io/debezium/**"
@@ -34,7 +34,7 @@ on:
     - cron: '15 1/6 * * *'
   workflow_dispatch:
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: write
@@ -70,7 +70,7 @@ jobs:
     timeout-minutes: 60
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event_name == 'workflow_dispatch' ||
       github.event.comment.body == 'Run Java_Debezium_IO_Direct PreCommit'
@@ -117,6 +117,7 @@ jobs:
         with:
           commit: '${{ env.prsha || env.GITHUB_SHA }}'
           comment_mode: ${{ github.event_name == 'issue_comment'  && 'always' 
|| 'off' }}
+          check_run: ${{ github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository }}
           files: '**/build/test-results/**/*.xml'
           large_files: true
       - name: Archive SpotBugs Results
@@ -127,7 +128,7 @@ jobs:
           path: '**/build/reports/spotbugs/*.html'
       - name: Publish SpotBugs Results
         uses: jwgmeligmeyling/[email protected]
-        if: always()
+        if: always() && (github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository)
         with:
           name: Publish SpotBugs
           path: '**/build/reports/spotbugs/*.html'
diff --git a/.github/workflows/beam_PreCommit_Java_Delta_IO_Direct.yml 
b/.github/workflows/beam_PreCommit_Java_Delta_IO_Direct.yml
index d7624d5ccd3..1314683e741 100644
--- a/.github/workflows/beam_PreCommit_Java_Delta_IO_Direct.yml
+++ b/.github/workflows/beam_PreCommit_Java_Delta_IO_Direct.yml
@@ -25,7 +25,7 @@ on:
       - "sdks/java/expansion-service/**"
       - "sdks/java/io/expansion-service/**"
       - ".github/workflows/beam_PreCommit_Java_Delta_IO_Direct.yml"
-  pull_request_target:
+  pull_request:
     branches: ['master', 'release-*']
     paths:
       - "sdks/java/io/delta/**"
@@ -40,7 +40,7 @@ on:
     - cron: '15 2/6 * * *'
   workflow_dispatch:
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: write
@@ -76,7 +76,7 @@ jobs:
     timeout-minutes: 60
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event_name == 'workflow_dispatch' ||
       github.event.comment.body == 'Run Java_Delta_IO_Direct PreCommit'
@@ -117,6 +117,7 @@ jobs:
         with:
           commit: '${{ env.prsha || env.GITHUB_SHA }}'
           comment_mode: ${{ github.event_name == 'issue_comment'  && 'always' 
|| 'off' }}
+          check_run: ${{ github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository }}
           files: '**/build/test-results/**/*.xml'
           large_files: true
       - name: Archive SpotBugs Results
@@ -127,7 +128,7 @@ jobs:
           path: '**/build/reports/spotbugs/*.html'
       - name: Publish SpotBugs Results
         uses: jwgmeligmeyling/[email protected]
-        if: always()
+        if: always() && (github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository)
         with:
           name: Publish SpotBugs
           path: '**/build/reports/spotbugs/*.html'
diff --git a/.github/workflows/beam_PreCommit_Java_ElasticSearch_IO_Direct.yml 
b/.github/workflows/beam_PreCommit_Java_ElasticSearch_IO_Direct.yml
index bec4fe27e8e..2c0a75b5fce 100644
--- a/.github/workflows/beam_PreCommit_Java_ElasticSearch_IO_Direct.yml
+++ b/.github/workflows/beam_PreCommit_Java_ElasticSearch_IO_Direct.yml
@@ -23,7 +23,7 @@ on:
       - "sdks/java/io/elasticsearch/**"
       - "sdks/java/io/elasticsearch-tests/**"
       - ".github/workflows/beam_PreCommit_Java_ElasticSearch_IO_Direct.yml"
-  pull_request_target:
+  pull_request:
     branches: ['master', 'release-*']
     paths:
       - "sdks/java/io/elasticsearch/**"
@@ -36,7 +36,7 @@ on:
     - cron: '30 1/6 * * *'
   workflow_dispatch:
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: write
@@ -72,7 +72,7 @@ jobs:
     timeout-minutes: 60
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event_name == 'workflow_dispatch' ||
       github.event.comment.body == 'Run Java_ElasticSearch_IO_Direct PreCommit'
@@ -119,6 +119,7 @@ jobs:
         with:
           commit: '${{ env.prsha || env.GITHUB_SHA }}'
           comment_mode: ${{ github.event_name == 'issue_comment'  && 'always' 
|| 'off' }}
+          check_run: ${{ github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository }}
           files: '**/build/test-results/**/*.xml'
           large_files: true
       - name: Archive SpotBugs Results
@@ -129,7 +130,7 @@ jobs:
           path: '**/build/reports/spotbugs/*.html'
       - name: Publish SpotBugs Results
         uses: jwgmeligmeyling/[email protected]
-        if: always()
+        if: always() && (github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository)
         with:
           name: Publish SpotBugs
           path: '**/build/reports/spotbugs/*.html'
diff --git a/.github/workflows/beam_PreCommit_Java_Examples_Dataflow.yml 
b/.github/workflows/beam_PreCommit_Java_Examples_Dataflow.yml
index 7c1286ce418..7d689a3b055 100644
--- a/.github/workflows/beam_PreCommit_Java_Examples_Dataflow.yml
+++ b/.github/workflows/beam_PreCommit_Java_Examples_Dataflow.yml
@@ -29,7 +29,7 @@ on:
       - 'examples/kotlin/**'
       - 'release/**'
       - '.github/workflows/beam_PreCommit_Java_Examples_Dataflow.yml'
-  pull_request_target:
+  pull_request:
     branches: ['master', 'release-*']
     paths:
       - 'model/**'
@@ -56,7 +56,7 @@ env:
   GRADLE_ENTERPRISE_CACHE_USERNAME: ${{ secrets.GE_CACHE_USERNAME }}
   GRADLE_ENTERPRISE_CACHE_PASSWORD: ${{ secrets.GE_CACHE_PASSWORD }}
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: write
@@ -82,7 +82,7 @@ jobs:
         job_phrase: [Run Java_Examples_Dataflow PreCommit]
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event_name == 'workflow_dispatch' ||
       github.event.comment.body == 'Run Java_Examples_Dataflow PreCommit'
@@ -120,5 +120,6 @@ jobs:
         with:
           commit: '${{ env.prsha || env.GITHUB_SHA }}'
           comment_mode: ${{ github.event_name == 'issue_comment'  && 'always' 
|| 'off' }}
+          check_run: ${{ github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository }}
           files: '**/build/test-results/**/*.xml'
           large_files: true
diff --git a/.github/workflows/beam_PreCommit_Java_Examples_Dataflow_Java11.yml 
b/.github/workflows/beam_PreCommit_Java_Examples_Dataflow_Java11.yml
index 3504d06bbba..9251b86aa94 100644
--- a/.github/workflows/beam_PreCommit_Java_Examples_Dataflow_Java11.yml
+++ b/.github/workflows/beam_PreCommit_Java_Examples_Dataflow_Java11.yml
@@ -27,7 +27,7 @@ on:
     - 'examples/kotlin/**'
     - 'release/**'
     - '.github/workflows/beam_PreCommit_Java_Examples_Dataflow_Java11.yml'
-  pull_request_target:
+  pull_request:
     branches: ['master', 'release-*']
     paths:
     - 'model/**'
@@ -44,7 +44,7 @@ on:
   - cron: '30 1/6 * * *'
   workflow_dispatch:
 
-# Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: write
@@ -80,7 +80,7 @@ jobs:
     timeout-minutes: 75
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event_name == 'workflow_dispatch' ||
       github.event.comment.body == 'Run Java_Examples_Dataflow_Java11 
PreCommit'
@@ -135,6 +135,7 @@ jobs:
       with:
         commit: '${{ env.prsha || env.GITHUB_SHA }}'
         comment_mode: ${{ github.event_name == 'issue_comment'  && 'always' || 
'off' }}
+        check_run: ${{ github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository }}
         files: '**/build/test-results/**/*.xml'
         large_files: true
     - name: Archive SpotBugs Results
diff --git 
a/.github/workflows/beam_PreCommit_Java_File-schema-transform_IO_Direct.yml 
b/.github/workflows/beam_PreCommit_Java_File-schema-transform_IO_Direct.yml
index 3f9223eaba6..20e78463cfe 100644
--- a/.github/workflows/beam_PreCommit_Java_File-schema-transform_IO_Direct.yml
+++ b/.github/workflows/beam_PreCommit_Java_File-schema-transform_IO_Direct.yml
@@ -22,7 +22,7 @@ on:
     paths:
       - "sdks/java/io/file-schema-transform/**"
       - 
".github/workflows/beam_PreCommit_Java_File-schema-transform_IO_Direct.yml"
-  pull_request_target:
+  pull_request:
     branches: ['master', 'release-*']
     paths:
       - "sdks/java/io/file-schema-transform/**"
@@ -34,7 +34,7 @@ on:
     - cron: '30 1/6 * * *'
   workflow_dispatch:
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: write
@@ -70,7 +70,7 @@ jobs:
     timeout-minutes: 60
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event_name == 'workflow_dispatch' ||
       github.event.comment.body == 'Run Java_File-schema-transform_IO_Direct 
PreCommit'
@@ -107,6 +107,7 @@ jobs:
         with:
           commit: '${{ env.prsha || env.GITHUB_SHA }}'
           comment_mode: ${{ github.event_name == 'issue_comment'  && 'always' 
|| 'off' }}
+          check_run: ${{ github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository }}
           files: '**/build/test-results/**/*.xml'
           large_files: true
       - name: Archive SpotBugs Results
@@ -117,7 +118,7 @@ jobs:
           path: '**/build/reports/spotbugs/*.html'
       - name: Publish SpotBugs Results
         uses: jwgmeligmeyling/[email protected]
-        if: always()
+        if: always() && (github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository)
         with:
           name: Publish SpotBugs
           path: '**/build/reports/spotbugs/*.html'
diff --git a/.github/workflows/beam_PreCommit_Java_Flink_Versions.yml 
b/.github/workflows/beam_PreCommit_Java_Flink_Versions.yml
index f7832008b69..8e54fddb06e 100644
--- a/.github/workflows/beam_PreCommit_Java_Flink_Versions.yml
+++ b/.github/workflows/beam_PreCommit_Java_Flink_Versions.yml
@@ -24,7 +24,7 @@ on:
       - 'runners/flink/**'
       - 'release/**'
       - '.github/workflows/beam_PreCommit_Java_Flink_Versions.yml'
-  pull_request_target:
+  pull_request:
     branches: ['master', 'release-*']
     paths:
       - 'model/**'
@@ -71,7 +71,7 @@ jobs:
     if: |
       github.event_name == 'push' ||
       github.event_name == 'workflow_dispatch' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event.comment.body == 'Run Java_Flink_Versions PreCommit'
     steps:
@@ -106,5 +106,6 @@ jobs:
         with:
           commit: '${{ env.prsha || env.GITHUB_SHA }}'
           comment_mode: ${{ github.event_name == 'issue_comment'  && 'always' 
|| 'off' }}
+          check_run: ${{ github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository }}
           files: '**/build/test-results/**/*.xml'
           large_files: true
diff --git a/.github/workflows/beam_PreCommit_Java_GCP_IO_Direct.yml 
b/.github/workflows/beam_PreCommit_Java_GCP_IO_Direct.yml
index 3e2c9c16248..8b835810e8a 100644
--- a/.github/workflows/beam_PreCommit_Java_GCP_IO_Direct.yml
+++ b/.github/workflows/beam_PreCommit_Java_GCP_IO_Direct.yml
@@ -31,7 +31,7 @@ on:
       - "sdks/java/io/expansion-service/**"
       - "sdks/java/io/google-cloud-platform/**"
       - ".github/workflows/beam_PreCommit_Java_GCP_IO_Direct.yml"
-  pull_request_target:
+  pull_request:
     branches: ['master', 'release-*']
     paths:
       - "buildSrc/**"
@@ -52,7 +52,7 @@ on:
     - cron: '30 1/6 * * *'
   workflow_dispatch:
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: write
@@ -105,7 +105,7 @@ jobs:
     timeout-minutes: 180
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event_name == 'workflow_dispatch' ||
       github.event.comment.body == 'Run Java_GCP_IO_Direct PreCommit'
@@ -142,6 +142,7 @@ jobs:
         with:
           commit: '${{ env.prsha || env.GITHUB_SHA }}'
           comment_mode: ${{ github.event_name == 'issue_comment'  && 'always' 
|| 'off' }}
+          check_run: ${{ github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository }}
           files: '**/build/test-results/**/*.xml'
           large_files: true
       - name: Archive SpotBugs Results
diff --git a/.github/workflows/beam_PreCommit_Java_Google-ads_IO_Direct.yml 
b/.github/workflows/beam_PreCommit_Java_Google-ads_IO_Direct.yml
index 6d6ae12d1d1..adf1a48a2d5 100644
--- a/.github/workflows/beam_PreCommit_Java_Google-ads_IO_Direct.yml
+++ b/.github/workflows/beam_PreCommit_Java_Google-ads_IO_Direct.yml
@@ -22,7 +22,7 @@ on:
     paths:
     - "sdks/java/io/google-ads/**"
     - ".github/workflows/beam_PreCommit_Java_Google-ads_IO_Direct.yml"
-  pull_request_target:
+  pull_request:
     branches: ['master', 'release-*']
     paths:
     - "sdks/java/io/google-ads/**"
@@ -34,7 +34,7 @@ on:
   - cron: '0 */6 * * *'
   workflow_dispatch:
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: write
@@ -70,7 +70,7 @@ jobs:
     timeout-minutes: 60
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event_name == 'workflow_dispatch' ||
       github.event.comment.body == 'Run Java_Google-ads_IO_Direct PreCommit'
@@ -104,6 +104,7 @@ jobs:
       with:
         commit: '${{ env.prsha || env.GITHUB_SHA }}'
         comment_mode: ${{ github.event_name == 'issue_comment'  && 'always' || 
'off' }}
+        check_run: ${{ github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository }}
         files: '**/build/test-results/**/*.xml'
         large_files: true
     - name: Archive SpotBugs Results
@@ -114,7 +115,7 @@ jobs:
         path: '**/build/reports/spotbugs/*.html'
     - name: Publish SpotBugs Results
       uses: jwgmeligmeyling/[email protected]
-      if: always()
+      if: always() && (github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository)
       with:
         name: Publish SpotBugs
         path: '**/build/reports/spotbugs/*.html'
diff --git a/.github/workflows/beam_PreCommit_Java_HBase_IO_Direct.yml 
b/.github/workflows/beam_PreCommit_Java_HBase_IO_Direct.yml
index e5fdaf5ebf6..1e3fcffe567 100644
--- a/.github/workflows/beam_PreCommit_Java_HBase_IO_Direct.yml
+++ b/.github/workflows/beam_PreCommit_Java_HBase_IO_Direct.yml
@@ -23,7 +23,7 @@ on:
       - "sdks/java/io/hbase/**"
       - "sdks/java/io/hadoop-common/**"
       - ".github/workflows/beam_PreCommit_Java_HBase_IO_Direct.yml"
-  pull_request_target:
+  pull_request:
     branches: ['master', 'release-*']
     paths:
       - "sdks/java/io/hbase/**"
@@ -36,7 +36,7 @@ on:
     - cron: '45 1/6 * * *'
   workflow_dispatch:
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: write
@@ -72,7 +72,7 @@ jobs:
     timeout-minutes: 60
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event_name == 'workflow_dispatch' ||
       github.event.comment.body == 'Run Java_HBase_IO_Direct PreCommit'
@@ -110,6 +110,7 @@ jobs:
         with:
           commit: '${{ env.prsha || env.GITHUB_SHA }}'
           comment_mode: ${{ github.event_name == 'issue_comment'  && 'always' 
|| 'off' }}
+          check_run: ${{ github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository }}
           files: '**/build/test-results/**/*.xml'
           large_files: true
       - name: Archive SpotBugs Results
@@ -120,7 +121,7 @@ jobs:
           path: '**/build/reports/spotbugs/*.html'
       - name: Publish SpotBugs Results
         uses: jwgmeligmeyling/[email protected]
-        if: always()
+        if: always() && (github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository)
         with:
           name: Publish SpotBugs
           path: '**/build/reports/spotbugs/*.html'
diff --git a/.github/workflows/beam_PreCommit_Java_HCatalog_IO_Direct.yml 
b/.github/workflows/beam_PreCommit_Java_HCatalog_IO_Direct.yml
index d8c15259c30..1b753bdb28f 100644
--- a/.github/workflows/beam_PreCommit_Java_HCatalog_IO_Direct.yml
+++ b/.github/workflows/beam_PreCommit_Java_HCatalog_IO_Direct.yml
@@ -23,7 +23,7 @@ on:
       - "sdks/java/io/hcatalog/**"
       - "sdks/java/io/hadoop-common/**"
       - ".github/workflows/beam_PreCommit_Java_HCatalog_IO_Direct.yml"
-  pull_request_target:
+  pull_request:
     branches: ['master', 'release-*']
     paths:
       - "sdks/java/io/hcatalog/**"
@@ -36,7 +36,7 @@ on:
     - cron: '45 1/6 * * *'
   workflow_dispatch:
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: write
@@ -72,7 +72,7 @@ jobs:
     timeout-minutes: 60
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event_name == 'workflow_dispatch' ||
       github.event.comment.body == 'Run Java_HCatalog_IO_Direct PreCommit'
@@ -110,6 +110,7 @@ jobs:
         with:
           commit: '${{ env.prsha || env.GITHUB_SHA }}'
           comment_mode: ${{ github.event_name == 'issue_comment'  && 'always' 
|| 'off' }}
+          check_run: ${{ github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository }}
           files: '**/build/test-results/**/*.xml'
           large_files: true
       - name: Archive SpotBugs Results
@@ -120,7 +121,7 @@ jobs:
           path: '**/build/reports/spotbugs/*.html'
       - name: Publish SpotBugs Results
         uses: jwgmeligmeyling/[email protected]
-        if: always()
+        if: always() && (github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository)
         with:
           name: Publish SpotBugs
           path: '**/build/reports/spotbugs/*.html'
diff --git a/.github/workflows/beam_PreCommit_Java_Hadoop_IO_Direct.yml 
b/.github/workflows/beam_PreCommit_Java_Hadoop_IO_Direct.yml
index 9b53c687525..c6a32d766cf 100644
--- a/.github/workflows/beam_PreCommit_Java_Hadoop_IO_Direct.yml
+++ b/.github/workflows/beam_PreCommit_Java_Hadoop_IO_Direct.yml
@@ -35,7 +35,7 @@ on:
       - "sdks/java/io/hadoop-common/**"
       - "sdks/java/io/hadoop-format/**"
       - ".github/workflows/beam_PreCommit_Java_Hadoop_IO_Direct.yml"
-  pull_request_target:
+  pull_request:
     branches: ['master', 'release-*']
     paths:
       - "sdks/java/io/hadoop-file-system/**"
@@ -60,7 +60,7 @@ on:
     - cron: '45 1/6 * * *'
   workflow_dispatch:
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: write
@@ -96,7 +96,7 @@ jobs:
     timeout-minutes: 60
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event_name == 'workflow_dispatch' ||
       github.event.comment.body == 'Run Java_Hadoop_IO_Direct PreCommit'
@@ -146,6 +146,7 @@ jobs:
         with:
           commit: '${{ env.prsha || env.GITHUB_SHA }}'
           comment_mode: ${{ github.event_name == 'issue_comment'  && 'always' 
|| 'off' }}
+          check_run: ${{ github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository }}
           files: '**/build/test-results/**/*.xml'
           large_files: true
       - name: Archive SpotBugs Results
@@ -156,7 +157,7 @@ jobs:
           path: '**/build/reports/spotbugs/*.html'
       - name: Publish SpotBugs Results
         uses: jwgmeligmeyling/[email protected]
-        if: always()
+        if: always() && (github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository)
         with:
           name: Publish SpotBugs
           path: '**/build/reports/spotbugs/*.html'
diff --git a/.github/workflows/beam_PreCommit_Java_IOs_Direct.yml 
b/.github/workflows/beam_PreCommit_Java_IOs_Direct.yml
index a0c7197d947..a6cdf172122 100644
--- a/.github/workflows/beam_PreCommit_Java_IOs_Direct.yml
+++ b/.github/workflows/beam_PreCommit_Java_IOs_Direct.yml
@@ -25,7 +25,7 @@ on:
       - "sdks/java/extensions/kafka-factories/**"
       - "buildSrc/**"
       - ".github/workflows/beam_PreCommit_Java_IOs_Direct.yml"
-  pull_request_target:
+  pull_request:
     branches: ['master', 'release-*']
     paths:
       - "sdks/java/io/common/**"
@@ -38,7 +38,7 @@ on:
   workflow_dispatch:
 # disable cron run because the tasks are covered by the single IO precommits 
below
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: write
@@ -74,7 +74,7 @@ jobs:
     timeout-minutes: 120
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       github.event_name == 'workflow_dispatch' ||
       github.event.comment.body == 'Run Java_IOs_Direct PreCommit'
     runs-on: [self-hosted, ubuntu-24.04, main]
@@ -123,6 +123,7 @@ jobs:
         with:
           commit: '${{ env.prsha || env.GITHUB_SHA }}'
           comment_mode: ${{ github.event_name == 'issue_comment'  && 'always' 
|| 'off' }}
+          check_run: ${{ github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository }}
           files: '**/build/test-results/**/*.xml'
           large_files: true
       - name: Archive SpotBugs Results
@@ -133,7 +134,7 @@ jobs:
           path: '**/build/reports/spotbugs/*.html'
       - name: Publish SpotBugs Results
         uses: jwgmeligmeyling/[email protected]
-        if: always()
+        if: always() && (github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository)
         with:
           name: Publish SpotBugs
           path: '**/build/reports/spotbugs/*.html'
diff --git a/.github/workflows/beam_PreCommit_Java_InfluxDb_IO_Direct.yml 
b/.github/workflows/beam_PreCommit_Java_InfluxDb_IO_Direct.yml
index 3ff0d49bd64..d394b527d72 100644
--- a/.github/workflows/beam_PreCommit_Java_InfluxDb_IO_Direct.yml
+++ b/.github/workflows/beam_PreCommit_Java_InfluxDb_IO_Direct.yml
@@ -22,7 +22,7 @@ on:
     paths:
       - "sdks/java/io/influxdb/**"
       - ".github/workflows/beam_PreCommit_Java_InfluxDb_IO_Direct.yml"
-  pull_request_target:
+  pull_request:
     branches: ['master', 'release-*']
     paths:
       - "sdks/java/io/influxdb/**"
@@ -34,7 +34,7 @@ on:
     - cron: '45 1/6 * * *'
   workflow_dispatch:
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: write
@@ -70,7 +70,7 @@ jobs:
     timeout-minutes: 60
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event_name == 'workflow_dispatch' ||
       github.event.comment.body == 'Run Java_InfluxDb_IO_Direct PreCommit'
@@ -106,6 +106,7 @@ jobs:
         with:
           commit: '${{ env.prsha || env.GITHUB_SHA }}'
           comment_mode: ${{ github.event_name == 'issue_comment'  && 'always' 
|| 'off' }}
+          check_run: ${{ github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository }}
           files: '**/build/test-results/**/*.xml'
           large_files: true
       - name: Archive SpotBugs Results
@@ -116,7 +117,7 @@ jobs:
           path: '**/build/reports/spotbugs/*.html'
       - name: Publish SpotBugs Results
         uses: jwgmeligmeyling/[email protected]
-        if: always()
+        if: always() && (github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository)
         with:
           name: Publish SpotBugs
           path: '**/build/reports/spotbugs/*.html'
diff --git a/.github/workflows/beam_PreCommit_Java_JDBC_IO_Direct.yml 
b/.github/workflows/beam_PreCommit_Java_JDBC_IO_Direct.yml
index 96621b49435..67aa744ab0f 100644
--- a/.github/workflows/beam_PreCommit_Java_JDBC_IO_Direct.yml
+++ b/.github/workflows/beam_PreCommit_Java_JDBC_IO_Direct.yml
@@ -22,7 +22,7 @@ on:
     paths:
       - "sdks/java/io/jdbc/**"
       - ".github/workflows/beam_PreCommit_Java_JDBC_IO_Direct.yml"
-  pull_request_target:
+  pull_request:
     branches: ['master', 'release-*']
     paths:
       - "sdks/java/io/jdbc/**"
@@ -34,7 +34,7 @@ on:
     - cron: '45 1/6 * * *'
   workflow_dispatch:
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: write
@@ -70,7 +70,7 @@ jobs:
     timeout-minutes: 60
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event_name == 'workflow_dispatch' ||
       github.event.comment.body == 'Run Java_JDBC_IO_Direct PreCommit'
@@ -113,6 +113,7 @@ jobs:
         with:
           commit: '${{ env.prsha || env.GITHUB_SHA }}'
           comment_mode: ${{ github.event_name == 'issue_comment'  && 'always' 
|| 'off' }}
+          check_run: ${{ github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository }}
           files: '**/build/test-results/**/*.xml'
           large_files: true
       - name: Archive SpotBugs Results
@@ -123,7 +124,7 @@ jobs:
           path: '**/build/reports/spotbugs/*.html'
       - name: Publish SpotBugs Results
         uses: jwgmeligmeyling/[email protected]
-        if: always()
+        if: always() && (github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository)
         with:
           name: Publish SpotBugs
           path: '**/build/reports/spotbugs/*.html'
diff --git a/.github/workflows/beam_PreCommit_Java_Jms_IO_Direct.yml 
b/.github/workflows/beam_PreCommit_Java_Jms_IO_Direct.yml
index 3336c214414..e26aee93425 100644
--- a/.github/workflows/beam_PreCommit_Java_Jms_IO_Direct.yml
+++ b/.github/workflows/beam_PreCommit_Java_Jms_IO_Direct.yml
@@ -22,7 +22,7 @@ on:
     paths:
       - "sdks/java/io/jms/**"
       - ".github/workflows/beam_PreCommit_Java_Jms_IO_Direct.yml"
-  pull_request_target:
+  pull_request:
     branches: ['master', 'release-*']
     paths:
       - "sdks/java/io/jms/**"
@@ -34,7 +34,7 @@ on:
     - cron: '45 1/6 * * *'
   workflow_dispatch:
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: write
@@ -70,7 +70,7 @@ jobs:
     timeout-minutes: 60
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event_name == 'workflow_dispatch' ||
       github.event.comment.body == 'Run Java_Jms_IO_Direct PreCommit'
@@ -113,6 +113,7 @@ jobs:
         with:
           commit: '${{ env.prsha || env.GITHUB_SHA }}'
           comment_mode: ${{ github.event_name == 'issue_comment'  && 'always' 
|| 'off' }}
+          check_run: ${{ github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository }}
           files: '**/build/test-results/**/*.xml'
           large_files: true
       - name: Archive SpotBugs Results
@@ -123,7 +124,7 @@ jobs:
           path: '**/build/reports/spotbugs/*.html'
       - name: Publish SpotBugs Results
         uses: jwgmeligmeyling/[email protected]
-        if: always()
+        if: always() && (github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository)
         with:
           name: Publish SpotBugs
           path: '**/build/reports/spotbugs/*.html'
diff --git a/.github/workflows/beam_PreCommit_Java_Kafka_IO_Direct.yml 
b/.github/workflows/beam_PreCommit_Java_Kafka_IO_Direct.yml
index c9f484b075f..a65faa35bfe 100644
--- a/.github/workflows/beam_PreCommit_Java_Kafka_IO_Direct.yml
+++ b/.github/workflows/beam_PreCommit_Java_Kafka_IO_Direct.yml
@@ -26,7 +26,7 @@ on:
       - "sdks/java/io/synthetic/**"
       - "sdks/java/io/expansion-service/**"
       - ".github/workflows/beam_PreCommit_Java_Kafka_IO_Direct.yml"
-  pull_request_target:
+  pull_request:
     branches: ['master', 'release-*']
     paths:
       - "sdks/java/io/kafka/**"
@@ -42,7 +42,7 @@ on:
     - cron: '45 1/6 * * *'
   workflow_dispatch:
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: write
@@ -78,7 +78,7 @@ jobs:
     timeout-minutes: 120
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event_name == 'workflow_dispatch' ||
       github.event.comment.body == 'Run Java_Kafka_IO_Direct PreCommit'
@@ -115,6 +115,7 @@ jobs:
         with:
           commit: '${{ env.prsha || env.GITHUB_SHA }}'
           comment_mode: ${{ github.event_name == 'issue_comment'  && 'always' 
|| 'off' }}
+          check_run: ${{ github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository }}
           files: '**/build/test-results/**/*.xml'
           large_files: true
       - name: Archive SpotBugs Results
@@ -125,7 +126,7 @@ jobs:
           path: '**/build/reports/spotbugs/*.html'
       - name: Publish SpotBugs Results
         uses: jwgmeligmeyling/[email protected]
-        if: always()
+        if: always() && (github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository)
         with:
           name: Publish SpotBugs
           path: '**/build/reports/spotbugs/*.html'
diff --git a/.github/workflows/beam_PreCommit_Java_Kafka_Streams_Runner.yml 
b/.github/workflows/beam_PreCommit_Java_Kafka_Streams_Runner.yml
index 9d6e3eceab1..21a4c685e89 100644
--- a/.github/workflows/beam_PreCommit_Java_Kafka_Streams_Runner.yml
+++ b/.github/workflows/beam_PreCommit_Java_Kafka_Streams_Runner.yml
@@ -22,7 +22,7 @@ on:
     paths:
       - "runners/kafka-streams/**"
       - ".github/workflows/beam_PreCommit_Java_Kafka_Streams_Runner.yml"
-  pull_request_target:
+  pull_request:
     branches: ['master', 'release-*']
     paths:
       - "runners/kafka-streams/**"
@@ -34,7 +34,7 @@ on:
     - cron: '15 2/6 * * *'
   workflow_dispatch:
 
-# Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: write
@@ -70,7 +70,7 @@ jobs:
     timeout-minutes: 60
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event_name == 'workflow_dispatch' ||
       github.event.comment.body == 'Run Java_Kafka_Streams_Runner PreCommit'
@@ -103,6 +103,7 @@ jobs:
         with:
           commit: '${{ env.prsha || env.GITHUB_SHA }}'
           comment_mode: ${{ github.event_name == 'issue_comment'  && 'always' 
|| 'off' }}
+          check_run: ${{ github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository }}
           files: '**/build/test-results/**/*.xml'
           large_files: true
       - name: Archive SpotBugs Results
@@ -113,7 +114,7 @@ jobs:
           path: '**/build/reports/spotbugs/*.html'
       - name: Publish SpotBugs Results
         uses: jwgmeligmeyling/[email protected]
-        if: always()
+        if: always() && (github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository)
         with:
           name: Publish SpotBugs
           path: '**/build/reports/spotbugs/*.html'
diff --git a/.github/workflows/beam_PreCommit_Java_Kudu_IO_Direct.yml 
b/.github/workflows/beam_PreCommit_Java_Kudu_IO_Direct.yml
index 70617ceffbc..dea00612abb 100644
--- a/.github/workflows/beam_PreCommit_Java_Kudu_IO_Direct.yml
+++ b/.github/workflows/beam_PreCommit_Java_Kudu_IO_Direct.yml
@@ -22,7 +22,7 @@ on:
     paths:
       - "sdks/java/io/kudu/**"
       - ".github/workflows/beam_PreCommit_Java_Kudu_IO_Direct.yml"
-  pull_request_target:
+  pull_request:
     branches: ['master', 'release-*']
     paths:
       - "sdks/java/io/kudu/**"
@@ -34,7 +34,7 @@ on:
     - cron: '0 2/6 * * *'
   workflow_dispatch:
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: write
@@ -70,7 +70,7 @@ jobs:
     timeout-minutes: 60
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event_name == 'workflow_dispatch' ||
       github.event.comment.body == 'Run Java_Kudu_IO_Direct PreCommit'
@@ -106,6 +106,7 @@ jobs:
         with:
           commit: '${{ env.prsha || env.GITHUB_SHA }}'
           comment_mode: ${{ github.event_name == 'issue_comment'  && 'always' 
|| 'off' }}
+          check_run: ${{ github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository }}
           files: '**/build/test-results/**/*.xml'
           large_files: true
       - name: Archive SpotBugs Results
@@ -116,7 +117,7 @@ jobs:
           path: '**/build/reports/spotbugs/*.html'
       - name: Publish SpotBugs Results
         uses: jwgmeligmeyling/[email protected]
-        if: always()
+        if: always() && (github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository)
         with:
           name: Publish SpotBugs
           path: '**/build/reports/spotbugs/*.html'
diff --git a/.github/workflows/beam_PreCommit_Java_MongoDb_IO_Direct.yml 
b/.github/workflows/beam_PreCommit_Java_MongoDb_IO_Direct.yml
index afaec9df36f..a1e8eecb99b 100644
--- a/.github/workflows/beam_PreCommit_Java_MongoDb_IO_Direct.yml
+++ b/.github/workflows/beam_PreCommit_Java_MongoDb_IO_Direct.yml
@@ -22,7 +22,7 @@ on:
     paths:
       - "sdks/java/io/mongodb/**"
       - ".github/workflows/beam_PreCommit_Java_MongoDb_IO_Direct.yml"
-  pull_request_target:
+  pull_request:
     branches: ['master', 'release-*']
     paths:
       - "sdks/java/io/mongodb/**"
@@ -34,7 +34,7 @@ on:
     - cron: '0 2/6 * * *'
   workflow_dispatch:
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: write
@@ -70,7 +70,7 @@ jobs:
     timeout-minutes: 60
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event_name == 'workflow_dispatch' ||
       github.event.comment.body == 'Run Java_MongoDb_IO_Direct PreCommit'
@@ -106,6 +106,7 @@ jobs:
         with:
           commit: '${{ env.prsha || env.GITHUB_SHA }}'
           comment_mode: ${{ github.event_name == 'issue_comment'  && 'always' 
|| 'off' }}
+          check_run: ${{ github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository }}
           files: '**/build/test-results/**/*.xml'
           large_files: true
       - name: Archive SpotBugs Results
@@ -116,7 +117,7 @@ jobs:
           path: '**/build/reports/spotbugs/*.html'
       - name: Publish SpotBugs Results
         uses: jwgmeligmeyling/[email protected]
-        if: always()
+        if: always() && (github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository)
         with:
           name: Publish SpotBugs
           path: '**/build/reports/spotbugs/*.html'
diff --git a/.github/workflows/beam_PreCommit_Java_Mqtt_IO_Direct.yml 
b/.github/workflows/beam_PreCommit_Java_Mqtt_IO_Direct.yml
index 661cb7b67af..362491f6685 100644
--- a/.github/workflows/beam_PreCommit_Java_Mqtt_IO_Direct.yml
+++ b/.github/workflows/beam_PreCommit_Java_Mqtt_IO_Direct.yml
@@ -22,7 +22,7 @@ on:
     paths:
       - "sdks/java/io/mqtt/**"
       - ".github/workflows/beam_PreCommit_Java_Mqtt_IO_Direct.yml"
-  pull_request_target:
+  pull_request:
     branches: ['master', 'release-*']
     paths:
       - "sdks/java/io/mqtt/**"
@@ -34,7 +34,7 @@ on:
     - cron: '0 2/6 * * *'
   workflow_dispatch:
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: write
@@ -70,7 +70,7 @@ jobs:
     timeout-minutes: 60
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event_name == 'workflow_dispatch' ||
       github.event.comment.body == 'Run Java_Mqtt_IO_Direct PreCommit'
@@ -106,6 +106,7 @@ jobs:
         with:
           commit: '${{ env.prsha || env.GITHUB_SHA }}'
           comment_mode: ${{ github.event_name == 'issue_comment'  && 'always' 
|| 'off' }}
+          check_run: ${{ github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository }}
           files: '**/build/test-results/**/*.xml'
           large_files: true
       - name: Archive SpotBugs Results
@@ -116,7 +117,7 @@ jobs:
           path: '**/build/reports/spotbugs/*.html'
       - name: Publish SpotBugs Results
         uses: jwgmeligmeyling/[email protected]
-        if: always()
+        if: always() && (github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository)
         with:
           name: Publish SpotBugs
           path: '**/build/reports/spotbugs/*.html'
diff --git a/.github/workflows/beam_PreCommit_Java_Neo4j_IO_Direct.yml 
b/.github/workflows/beam_PreCommit_Java_Neo4j_IO_Direct.yml
index 97b52e1a52d..771b7815c4c 100644
--- a/.github/workflows/beam_PreCommit_Java_Neo4j_IO_Direct.yml
+++ b/.github/workflows/beam_PreCommit_Java_Neo4j_IO_Direct.yml
@@ -23,7 +23,7 @@ on:
       - "sdks/java/io/neo4j/**"
       - "sdks/java/testing/test-utils/**"
       - ".github/workflows/beam_PreCommit_Java_Neo4j_IO_Direct.yml"
-  pull_request_target:
+  pull_request:
     branches: ['master', 'release-*']
     paths:
       - "sdks/java/io/neo4j/**"
@@ -36,7 +36,7 @@ on:
     - cron: '0 2/6 * * *'
   workflow_dispatch:
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: write
@@ -72,7 +72,7 @@ jobs:
     timeout-minutes: 60
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event_name == 'workflow_dispatch' ||
       github.event.comment.body == 'Run Java_Neo4j_IO_Direct PreCommit'
@@ -115,6 +115,7 @@ jobs:
         with:
           commit: '${{ env.prsha || env.GITHUB_SHA }}'
           comment_mode: ${{ github.event_name == 'issue_comment'  && 'always' 
|| 'off' }}
+          check_run: ${{ github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository }}
           files: '**/build/test-results/**/*.xml'
           large_files: true
       - name: Archive SpotBugs Results
@@ -125,7 +126,7 @@ jobs:
           path: '**/build/reports/spotbugs/*.html'
       - name: Publish SpotBugs Results
         uses: jwgmeligmeyling/[email protected]
-        if: always()
+        if: always() && (github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository)
         with:
           name: Publish SpotBugs
           path: '**/build/reports/spotbugs/*.html'
diff --git a/.github/workflows/beam_PreCommit_Java_PVR_Flink_Batch.yml 
b/.github/workflows/beam_PreCommit_Java_PVR_Flink_Batch.yml
index 4bac198b2da..97d07292870 100644
--- a/.github/workflows/beam_PreCommit_Java_PVR_Flink_Batch.yml
+++ b/.github/workflows/beam_PreCommit_Java_PVR_Flink_Batch.yml
@@ -26,7 +26,7 @@ on:
       - 'runners/java-fn-execution/**'
       - 'sdks/java/core/src/test/java/org/apache/beam/sdk/transforms/**'
       - '.github/workflows/beam_PreCommit_Java_PVR_Flink_Batch.yml'
-  pull_request_target:
+  pull_request:
     branches: ['master', 'release-*']
     paths:
       - 'runners/flink/**'
@@ -45,7 +45,7 @@ concurrency:
   group: '${{ github.workflow }} @ ${{ github.event.pull_request.number || 
github.event.pull_request.head.label || github.sha || github.head_ref || 
github.ref }}-${{ github.event.schedule || github.event.comment.id || 
github.event.sender.login }}'
   cancel-in-progress: true
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: write
@@ -77,7 +77,7 @@ jobs:
     runs-on: [self-hosted, ubuntu-24.04, highmem]
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event_name == 'workflow_dispatch' ||
       github.event.comment.body == 'Run Java_PVR_Flink_Batch PreCommit'
diff --git a/.github/workflows/beam_PreCommit_Java_PVR_Flink_Docker.yml 
b/.github/workflows/beam_PreCommit_Java_PVR_Flink_Docker.yml
index 5dcddb1beff..dd5a2e2123d 100644
--- a/.github/workflows/beam_PreCommit_Java_PVR_Flink_Docker.yml
+++ b/.github/workflows/beam_PreCommit_Java_PVR_Flink_Docker.yml
@@ -28,7 +28,7 @@ on:
       - 'runners/flink/**'
       - 'runners/java-fn-execution/**'
       - '.github/workflows/beam_PreCommit_Java_PVR_Flink_Docker.yml'
-  pull_request_target:
+  pull_request:
     branches: ['master', 'release-*']
     paths:
       - 'sdks/java/core/src/test/java/org/apache/beam/sdk/**'
@@ -44,7 +44,7 @@ on:
     - cron: '15 2/6 * * *'
   workflow_dispatch:
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: write
@@ -81,7 +81,7 @@ jobs:
         job_phrase: [ Run Java_PVR_Flink_Docker PreCommit ]
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event_name == 'workflow_dispatch' ||
       github.event.comment.body == 'Run Java_PVR_Flink_Docker PreCommit'
@@ -116,5 +116,6 @@ jobs:
         with:
           commit: '${{ env.prsha || env.GITHUB_SHA }}'
           comment_mode: ${{ github.event_name == 'issue_comment'  && 'always' 
|| 'off' }}
+          check_run: ${{ github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository }}
           files: '**/build/test-results/**/*.xml'
           large_files: true
diff --git a/.github/workflows/beam_PreCommit_Java_PVR_Prism_Loopback.yml 
b/.github/workflows/beam_PreCommit_Java_PVR_Prism_Loopback.yml
index 56fcabddc9d..0fa5b68b3da 100644
--- a/.github/workflows/beam_PreCommit_Java_PVR_Prism_Loopback.yml
+++ b/.github/workflows/beam_PreCommit_Java_PVR_Prism_Loopback.yml
@@ -29,7 +29,7 @@ on:
       - 'runners/java-fn-execution/**'
       - 'sdks/java/core/src/test/java/org/apache/beam/sdk/transforms/**'
       - '.github/workflows/beam_PreCommit_Java_PVR_Prism_Loopback.yml'
-  pull_request_target:
+  pull_request:
     branches: ['master', 'release-*']
     paths:
       - 'model/**'
@@ -51,7 +51,7 @@ concurrency:
   group: '${{ github.workflow }} @ ${{ github.event.pull_request.number || 
github.event.pull_request.head.label || github.sha || github.head_ref || 
github.ref }}-${{ github.event.schedule || github.event.comment.id || 
github.event.sender.login }}'
   cancel-in-progress: true
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: write
@@ -83,7 +83,7 @@ jobs:
     runs-on: [self-hosted, ubuntu-24.04, main]
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event_name == 'workflow_dispatch' ||
       github.event.comment.body == 'Run Java_PVR_Prism_Loopback PreCommit'
diff --git a/.github/workflows/beam_PreCommit_Java_Parquet_IO_Direct.yml 
b/.github/workflows/beam_PreCommit_Java_Parquet_IO_Direct.yml
index 6e95f71673d..83ac819c891 100644
--- a/.github/workflows/beam_PreCommit_Java_Parquet_IO_Direct.yml
+++ b/.github/workflows/beam_PreCommit_Java_Parquet_IO_Direct.yml
@@ -22,7 +22,7 @@ on:
     paths:
       - "sdks/java/io/parquet/**"
       - ".github/workflows/beam_PreCommit_Java_Parquet_IO_Direct.yml"
-  pull_request_target:
+  pull_request:
     branches: ['master', 'release-*']
     paths:
       - "sdks/java/io/parquet/**"
@@ -34,7 +34,7 @@ on:
     - cron: '0 2/6 * * *'
   workflow_dispatch:
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: write
@@ -70,7 +70,7 @@ jobs:
     timeout-minutes: 60
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event_name == 'workflow_dispatch' ||
       github.event.comment.body == 'Run Java_Parquet_IO_Direct PreCommit'
@@ -106,6 +106,7 @@ jobs:
         with:
           commit: '${{ env.prsha || env.GITHUB_SHA }}'
           comment_mode: ${{ github.event_name == 'issue_comment'  && 'always' 
|| 'off' }}
+          check_run: ${{ github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository }}
           files: '**/build/test-results/**/*.xml'
           large_files: true
       - name: Archive SpotBugs Results
@@ -116,7 +117,7 @@ jobs:
           path: '**/build/reports/spotbugs/*.html'
       - name: Publish SpotBugs Results
         uses: jwgmeligmeyling/[email protected]
-        if: always()
+        if: always() && (github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository)
         with:
           name: Publish SpotBugs
           path: '**/build/reports/spotbugs/*.html'
diff --git a/.github/workflows/beam_PreCommit_Java_Pulsar_IO_Direct.yml 
b/.github/workflows/beam_PreCommit_Java_Pulsar_IO_Direct.yml
index ec825890bdc..d8b0ed2c31b 100644
--- a/.github/workflows/beam_PreCommit_Java_Pulsar_IO_Direct.yml
+++ b/.github/workflows/beam_PreCommit_Java_Pulsar_IO_Direct.yml
@@ -22,7 +22,7 @@ on:
     paths:
       - "sdks/java/io/pulsar/**"
       - ".github/workflows/beam_PreCommit_Java_Pulsar_IO_Direct.yml"
-  pull_request_target:
+  pull_request:
     branches: ['master', 'release-*']
     paths:
       - "sdks/java/io/pulsar/**"
@@ -34,7 +34,7 @@ on:
     - cron: '0 2/6 * * *'
   workflow_dispatch:
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: write
@@ -70,7 +70,7 @@ jobs:
     timeout-minutes: 60
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event_name == 'workflow_dispatch' ||
       github.event.comment.body == 'Run Java_Pulsar_IO_Direct PreCommit'
@@ -113,6 +113,7 @@ jobs:
         with:
           commit: '${{ env.prsha || env.GITHUB_SHA }}'
           comment_mode: ${{ github.event_name == 'issue_comment'  && 'always' 
|| 'off' }}
+          check_run: ${{ github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository }}
           files: '**/build/test-results/**/*.xml'
           large_files: true
       - name: Archive SpotBugs Results
@@ -123,7 +124,7 @@ jobs:
           path: '**/build/reports/spotbugs/*.html'
       - name: Publish SpotBugs Results
         uses: jwgmeligmeyling/[email protected]
-        if: always()
+        if: always() && (github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository)
         with:
           name: Publish SpotBugs
           path: '**/build/reports/spotbugs/*.html'
diff --git a/.github/workflows/beam_PreCommit_Java_RabbitMq_IO_Direct.yml 
b/.github/workflows/beam_PreCommit_Java_RabbitMq_IO_Direct.yml
index 5770b9f3e55..7ace8d30203 100644
--- a/.github/workflows/beam_PreCommit_Java_RabbitMq_IO_Direct.yml
+++ b/.github/workflows/beam_PreCommit_Java_RabbitMq_IO_Direct.yml
@@ -22,7 +22,7 @@ on:
     paths:
       - "sdks/java/io/rabbitmq/**"
       - ".github/workflows/beam_PreCommit_Java_RabbitMq_IO_Direct.yml"
-  pull_request_target:
+  pull_request:
     branches: ['master', 'release-*']
     paths:
       - "sdks/java/io/rabbitmq/**"
@@ -34,7 +34,7 @@ on:
     - cron: '15 2/6 * * *'
   workflow_dispatch:
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: write
@@ -70,7 +70,7 @@ jobs:
     timeout-minutes: 60
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event_name == 'workflow_dispatch' ||
       github.event.comment.body == 'Run Java_RabbitMq_IO_Direct PreCommit'
@@ -106,6 +106,7 @@ jobs:
         with:
           commit: '${{ env.prsha || env.GITHUB_SHA }}'
           comment_mode: ${{ github.event_name == 'issue_comment'  && 'always' 
|| 'off' }}
+          check_run: ${{ github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository }}
           files: '**/build/test-results/**/*.xml'
           large_files: true
       - name: Archive SpotBugs Results
@@ -116,7 +117,7 @@ jobs:
           path: '**/build/reports/spotbugs/*.html'
       - name: Publish SpotBugs Results
         uses: jwgmeligmeyling/[email protected]
-        if: always()
+        if: always() && (github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository)
         with:
           name: Publish SpotBugs
           path: '**/build/reports/spotbugs/*.html'
diff --git a/.github/workflows/beam_PreCommit_Java_Redis_IO_Direct.yml 
b/.github/workflows/beam_PreCommit_Java_Redis_IO_Direct.yml
index 9441278f83b..fff212cfe4b 100644
--- a/.github/workflows/beam_PreCommit_Java_Redis_IO_Direct.yml
+++ b/.github/workflows/beam_PreCommit_Java_Redis_IO_Direct.yml
@@ -22,7 +22,7 @@ on:
     paths:
       - "sdks/java/io/redis/**"
       - ".github/workflows/beam_PreCommit_Java_Redis_IO_Direct.yml"
-  pull_request_target:
+  pull_request:
     branches: ['master', 'release-*']
     paths:
       - "sdks/java/io/redis/**"
@@ -34,7 +34,7 @@ on:
     - cron: '15 2/6 * * *'
   workflow_dispatch:
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: write
@@ -70,7 +70,7 @@ jobs:
     timeout-minutes: 60
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event_name == 'workflow_dispatch' ||
       github.event.comment.body == 'Run Java_Redis_IO_Direct PreCommit'
@@ -106,6 +106,7 @@ jobs:
         with:
           commit: '${{ env.prsha || env.GITHUB_SHA }}'
           comment_mode: ${{ github.event_name == 'issue_comment'  && 'always' 
|| 'off' }}
+          check_run: ${{ github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository }}
           files: '**/build/test-results/**/*.xml'
           large_files: true
       - name: Archive SpotBugs Results
@@ -116,7 +117,7 @@ jobs:
           path: '**/build/reports/spotbugs/*.html'
       - name: Publish SpotBugs Results
         uses: jwgmeligmeyling/[email protected]
-        if: always()
+        if: always() && (github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository)
         with:
           name: Publish SpotBugs
           path: '**/build/reports/spotbugs/*.html'
diff --git 
a/.github/workflows/beam_PreCommit_Java_RequestResponse_IO_Direct.yml 
b/.github/workflows/beam_PreCommit_Java_RequestResponse_IO_Direct.yml
index b4e55572ab2..70edc7204cf 100644
--- a/.github/workflows/beam_PreCommit_Java_RequestResponse_IO_Direct.yml
+++ b/.github/workflows/beam_PreCommit_Java_RequestResponse_IO_Direct.yml
@@ -22,7 +22,7 @@ on:
     paths:
     - "sdks/java/io/rrio/**"
     - ".github/workflows/beam_PreCommit_Java_RequestResponse_IO_Direct.yml"
-  pull_request_target:
+  pull_request:
     branches: ['master', 'release-*']
     paths:
     - "sdks/java/io/rrio/**"
@@ -34,7 +34,7 @@ on:
   - cron: '0 */6 * * *'
   workflow_dispatch:
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: write
@@ -70,7 +70,7 @@ jobs:
     timeout-minutes: 60
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event_name == 'workflow_dispatch' ||
       github.event.comment.body == 'Run Java_RequestResponse_IO_Direct 
PreCommit'
@@ -104,6 +104,7 @@ jobs:
       with:
         commit: '${{ env.prsha || env.GITHUB_SHA }}'
         comment_mode: ${{ github.event_name == 'issue_comment'  && 'always' || 
'off' }}
+        check_run: ${{ github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository }}
         files: '**/build/test-results/**/*.xml'
         large_files: true
     - name: Archive SpotBugs Results
@@ -114,7 +115,7 @@ jobs:
         path: '**/build/reports/spotbugs/*.html'
     - name: Publish SpotBugs Results
       uses: jwgmeligmeyling/[email protected]
-      if: always()
+      if: always() && (github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository)
       with:
         name: Publish SpotBugs
         path: '**/build/reports/spotbugs/*.html'
diff --git a/.github/workflows/beam_PreCommit_Java_SingleStore_IO_Direct.yml 
b/.github/workflows/beam_PreCommit_Java_SingleStore_IO_Direct.yml
index f7d4347f3ee..217fcb07f21 100644
--- a/.github/workflows/beam_PreCommit_Java_SingleStore_IO_Direct.yml
+++ b/.github/workflows/beam_PreCommit_Java_SingleStore_IO_Direct.yml
@@ -23,7 +23,7 @@ on:
       - "sdks/java/io/singlestore/**"
       - "sdks/java/testing/test-utils/**"
       - ".github/workflows/beam_PreCommit_Java_SingleStore_IO_Direct.yml"
-  pull_request_target:
+  pull_request:
     branches: ['master', 'release-*']
     paths:
       - "sdks/java/io/singlestore/**"
@@ -36,7 +36,7 @@ on:
     - cron: '15 2/6 * * *'
   workflow_dispatch:
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: write
@@ -72,7 +72,7 @@ jobs:
     timeout-minutes: 60
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event_name == 'workflow_dispatch' ||
       github.event.comment.body == 'Run Java_SingleStore_IO_Direct PreCommit'
@@ -108,6 +108,7 @@ jobs:
         with:
           commit: '${{ env.prsha || env.GITHUB_SHA }}'
           comment_mode: ${{ github.event_name == 'issue_comment'  && 'always' 
|| 'off' }}
+          check_run: ${{ github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository }}
           files: '**/build/test-results/**/*.xml'
           large_files: true
       - name: Archive SpotBugs Results
@@ -118,7 +119,7 @@ jobs:
           path: '**/build/reports/spotbugs/*.html'
       - name: Publish SpotBugs Results
         uses: jwgmeligmeyling/[email protected]
-        if: always()
+        if: always() && (github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository)
         with:
           name: Publish SpotBugs
           path: '**/build/reports/spotbugs/*.html'
diff --git a/.github/workflows/beam_PreCommit_Java_Snowflake_IO_Direct.yml 
b/.github/workflows/beam_PreCommit_Java_Snowflake_IO_Direct.yml
index 678a0dbff19..7e529bc47f7 100644
--- a/.github/workflows/beam_PreCommit_Java_Snowflake_IO_Direct.yml
+++ b/.github/workflows/beam_PreCommit_Java_Snowflake_IO_Direct.yml
@@ -24,7 +24,7 @@ on:
       - "sdks/java/extensions/google-cloud-platform-core/**"
       - "sdks/java/testing/test-utils/**"
       - ".github/workflows/beam_PreCommit_Java_Snowflake_IO_Direct.yml"
-  pull_request_target:
+  pull_request:
     branches: ['master', 'release-*']
     paths:
       - "sdks/java/io/snowflake/**"
@@ -38,7 +38,7 @@ on:
     - cron: '15 2/6 * * *'
   workflow_dispatch:
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: write
@@ -74,7 +74,7 @@ jobs:
     timeout-minutes: 60
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event_name == 'workflow_dispatch' ||
       github.event.comment.body == 'Run Java_Snowflake_IO_Direct PreCommit'
@@ -117,6 +117,7 @@ jobs:
         with:
           commit: '${{ env.prsha || env.GITHUB_SHA }}'
           comment_mode: ${{ github.event_name == 'issue_comment'  && 'always' 
|| 'off' }}
+          check_run: ${{ github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository }}
           files: '**/build/test-results/**/*.xml'
           large_files: true
       - name: Archive SpotBugs Results
@@ -127,7 +128,7 @@ jobs:
           path: '**/build/reports/spotbugs/*.html'
       - name: Publish SpotBugs Results
         uses: jwgmeligmeyling/[email protected]
-        if: always()
+        if: always() && (github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository)
         with:
           name: Publish SpotBugs
           path: '**/build/reports/spotbugs/*.html'
diff --git a/.github/workflows/beam_PreCommit_Java_Solace_IO_Direct.yml 
b/.github/workflows/beam_PreCommit_Java_Solace_IO_Direct.yml
index 5d387b38b56..9d8a8ffe4c5 100644
--- a/.github/workflows/beam_PreCommit_Java_Solace_IO_Direct.yml
+++ b/.github/workflows/beam_PreCommit_Java_Solace_IO_Direct.yml
@@ -22,7 +22,7 @@ on:
     paths:
     - "sdks/java/io/solace/**"
     - ".github/workflows/beam_PreCommit_Java_Solace_IO_Direct.yml"
-  pull_request_target:
+  pull_request:
     branches: ['master', 'release-*']
     paths:
     - "sdks/java/io/solace/**"
@@ -34,7 +34,7 @@ on:
   - cron: '45 1/6 * * *'
   workflow_dispatch:
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: write
@@ -70,7 +70,7 @@ jobs:
     timeout-minutes: 60
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event_name == 'workflow_dispatch' ||
       github.event.comment.body == 'Run Java_Solace_IO_Direct PreCommit'
@@ -113,6 +113,7 @@ jobs:
       with:
         commit: '${{ env.prsha || env.GITHUB_SHA }}'
         comment_mode: ${{ github.event_name == 'issue_comment'  && 'always' || 
'off' }}
+        check_run: ${{ github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository }}
         files: '**/build/test-results/**/*.xml'
         large_files: true
     - name: Archive SpotBugs Results
@@ -123,7 +124,7 @@ jobs:
         path: '**/build/reports/spotbugs/*.html'
     - name: Publish SpotBugs Results
       uses: jwgmeligmeyling/[email protected]
-      if: always()
+      if: always() && (github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository)
       with:
         name: Publish SpotBugs
         path: '**/build/reports/spotbugs/*.html'
diff --git a/.github/workflows/beam_PreCommit_Java_Solr_IO_Direct.yml 
b/.github/workflows/beam_PreCommit_Java_Solr_IO_Direct.yml
index 6857e142cfb..efa8539ed97 100644
--- a/.github/workflows/beam_PreCommit_Java_Solr_IO_Direct.yml
+++ b/.github/workflows/beam_PreCommit_Java_Solr_IO_Direct.yml
@@ -22,7 +22,7 @@ on:
     paths:
       - "sdks/java/io/solr/**"
       - ".github/workflows/beam_PreCommit_Java_Solr_IO_Direct.yml"
-  pull_request_target:
+  pull_request:
     branches: ['master', 'release-*']
     paths:
       - "sdks/java/io/solr/**"
@@ -34,7 +34,7 @@ on:
     - cron: '15 2/6 * * *'
   workflow_dispatch:
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: write
@@ -70,7 +70,7 @@ jobs:
     timeout-minutes: 60
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event_name == 'workflow_dispatch' ||
       github.event.comment.body == 'Run Java_Solr_IO_Direct PreCommit'
@@ -106,6 +106,7 @@ jobs:
         with:
           commit: '${{ env.prsha || env.GITHUB_SHA }}'
           comment_mode: ${{ github.event_name == 'issue_comment'  && 'always' 
|| 'off' }}
+          check_run: ${{ github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository }}
           files: '**/build/test-results/**/*.xml'
           large_files: true
       - name: Archive SpotBugs Results
@@ -116,7 +117,7 @@ jobs:
           path: '**/build/reports/spotbugs/*.html'
       - name: Publish SpotBugs Results
         uses: jwgmeligmeyling/[email protected]
-        if: always()
+        if: always() && (github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository)
         with:
           name: Publish SpotBugs
           path: '**/build/reports/spotbugs/*.html'
diff --git a/.github/workflows/beam_PreCommit_Java_Spark_Versions.yml 
b/.github/workflows/beam_PreCommit_Java_Spark_Versions.yml
index 969dd363643..687e705b98c 100644
--- a/.github/workflows/beam_PreCommit_Java_Spark_Versions.yml
+++ b/.github/workflows/beam_PreCommit_Java_Spark_Versions.yml
@@ -24,7 +24,7 @@ on:
     paths:
       - 'runners/spark/**'
       - '.github/workflows/beam_PreCommit_Java_Spark_Versions.yml'
-  pull_request_target:
+  pull_request:
     branches: ['master', 'release-*']
     paths:
       - 'runners/spark/**'
@@ -41,7 +41,7 @@ concurrency:
   group: '${{ github.workflow }} @ ${{ github.event.pull_request.number || 
github.event.pull_request.head.label || github.sha || github.head_ref || 
github.ref }}-${{ github.event.schedule || github.event.comment.id || 
github.event.sender.login }}'
   cancel-in-progress: true
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: write
@@ -73,7 +73,7 @@ jobs:
     timeout-minutes: 120
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event_name == 'workflow_dispatch' ||
       github.event.comment.body == 'Run Java_Spark_Versions PreCommit'
@@ -112,5 +112,6 @@ jobs:
         with:
           commit: '${{ env.prsha || env.GITHUB_SHA }}'
           comment_mode: ${{ github.event_name == 'issue_comment'  && 'always' 
|| 'off' }}
+          check_run: ${{ github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository }}
           files: '**/build/test-results/**/*.xml'
           large_files: true
diff --git a/.github/workflows/beam_PreCommit_Java_Splunk_IO_Direct.yml 
b/.github/workflows/beam_PreCommit_Java_Splunk_IO_Direct.yml
index a5140f391d6..392b437323a 100644
--- a/.github/workflows/beam_PreCommit_Java_Splunk_IO_Direct.yml
+++ b/.github/workflows/beam_PreCommit_Java_Splunk_IO_Direct.yml
@@ -22,7 +22,7 @@ on:
     paths:
       - "sdks/java/io/splunk/**"
       - ".github/workflows/beam_PreCommit_Java_Splunk_IO_Direct.yml"
-  pull_request_target:
+  pull_request:
     branches: ['master', 'release-*']
     paths:
       - "sdks/java/io/splunk/**"
@@ -34,7 +34,7 @@ on:
     - cron: '30 2/6 * * *'
   workflow_dispatch:
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: write
@@ -70,7 +70,7 @@ jobs:
     timeout-minutes: 60
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event_name == 'workflow_dispatch' ||
       github.event.comment.body == 'Run Java_Splunk_IO_Direct PreCommit'
@@ -106,6 +106,7 @@ jobs:
         with:
           commit: '${{ env.prsha || env.GITHUB_SHA }}'
           comment_mode: ${{ github.event_name == 'issue_comment'  && 'always' 
|| 'off' }}
+          check_run: ${{ github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository }}
           files: '**/build/test-results/**/*.xml'
           large_files: true
       - name: Archive SpotBugs Results
@@ -116,7 +117,7 @@ jobs:
           path: '**/build/reports/spotbugs/*.html'
       - name: Publish SpotBugs Results
         uses: jwgmeligmeyling/[email protected]
-        if: always()
+        if: always() && (github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository)
         with:
           name: Publish SpotBugs
           path: '**/build/reports/spotbugs/*.html'
diff --git a/.github/workflows/beam_PreCommit_Java_Thrift_IO_Direct.yml 
b/.github/workflows/beam_PreCommit_Java_Thrift_IO_Direct.yml
index 515184ba5c7..de0e42e8f0c 100644
--- a/.github/workflows/beam_PreCommit_Java_Thrift_IO_Direct.yml
+++ b/.github/workflows/beam_PreCommit_Java_Thrift_IO_Direct.yml
@@ -22,7 +22,7 @@ on:
     paths:
       - "sdks/java/io/thrift/**"
       - ".github/workflows/beam_PreCommit_Java_Thrift_IO_Direct.yml"
-  pull_request_target:
+  pull_request:
     branches: ['master', 'release-*']
     paths:
       - "sdks/java/io/thrift/**"
@@ -34,7 +34,7 @@ on:
     - cron: '30 2/6 * * *'
   workflow_dispatch:
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: write
@@ -70,7 +70,7 @@ jobs:
     timeout-minutes: 60
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event_name == 'workflow_dispatch' ||
       github.event.comment.body == 'Run Java_Thrift_IO_Direct PreCommit'
@@ -106,6 +106,7 @@ jobs:
         with:
           commit: '${{ env.prsha || env.GITHUB_SHA }}'
           comment_mode: ${{ github.event_name == 'issue_comment'  && 'always' 
|| 'off' }}
+          check_run: ${{ github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository }}
           files: '**/build/test-results/**/*.xml'
           large_files: true
       - name: Archive SpotBugs Results
@@ -116,7 +117,7 @@ jobs:
           path: '**/build/reports/spotbugs/*.html'
       - name: Publish SpotBugs Results
         uses: jwgmeligmeyling/[email protected]
-        if: always()
+        if: always() && (github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository)
         with:
           name: Publish SpotBugs
           path: '**/build/reports/spotbugs/*.html'
diff --git a/.github/workflows/beam_PreCommit_Java_Tika_IO_Direct.yml 
b/.github/workflows/beam_PreCommit_Java_Tika_IO_Direct.yml
index fd4214ad420..76fc8f5d44e 100644
--- a/.github/workflows/beam_PreCommit_Java_Tika_IO_Direct.yml
+++ b/.github/workflows/beam_PreCommit_Java_Tika_IO_Direct.yml
@@ -22,7 +22,7 @@ on:
     paths:
       - "sdks/java/io/tika/**"
       - ".github/workflows/beam_PreCommit_Java_Tika_IO_Direct.yml"
-  pull_request_target:
+  pull_request:
     branches: ['master', 'release-*']
     paths:
       - "sdks/java/io/tika/**"
@@ -34,7 +34,7 @@ on:
     - cron: '30 2/6 * * *'
   workflow_dispatch:
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: write
@@ -70,7 +70,7 @@ jobs:
     timeout-minutes: 60
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event_name == 'workflow_dispatch' ||
       github.event.comment.body == 'Run Java_Tika_IO_Direct PreCommit'
@@ -106,6 +106,7 @@ jobs:
         with:
           commit: '${{ env.prsha || env.GITHUB_SHA }}'
           comment_mode: ${{ github.event_name == 'issue_comment'  && 'always' 
|| 'off' }}
+          check_run: ${{ github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository }}
           files: '**/build/test-results/**/*.xml'
           large_files: true
       - name: Archive SpotBugs Results
@@ -116,7 +117,7 @@ jobs:
           path: '**/build/reports/spotbugs/*.html'
       - name: Publish SpotBugs Results
         uses: jwgmeligmeyling/[email protected]
-        if: always()
+        if: always() && (github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository)
         with:
           name: Publish SpotBugs
           path: '**/build/reports/spotbugs/*.html'
diff --git a/.github/workflows/beam_PreCommit_Kotlin_Examples.yml 
b/.github/workflows/beam_PreCommit_Kotlin_Examples.yml
index 18ed78e29f0..1e35616251d 100644
--- a/.github/workflows/beam_PreCommit_Kotlin_Examples.yml
+++ b/.github/workflows/beam_PreCommit_Kotlin_Examples.yml
@@ -28,7 +28,7 @@ on:
     - 'examples/kotlin/**'
     - 'release/**'
     - '.github/workflows/beam_PreCommit_Kotlin_Examples.yml'
-  pull_request_target:
+  pull_request:
     branches: ['master', 'release-*']
     paths:
       - 'model/**'
@@ -51,7 +51,7 @@ concurrency:
   group: '${{ github.workflow }} @ ${{ github.event.pull_request.number || 
github.event.pull_request.head.label || github.sha || github.head_ref || 
github.ref }}-${{ github.event.schedule || github.event.comment.id || 
github.event.sender.login }}'
   cancel-in-progress: true
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: read
@@ -83,7 +83,7 @@ jobs:
         job_phrase: [Run Kotlin_Examples PreCommit]
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event_name == 'workflow_dispatch' ||
       github.event.comment.body == 'Run Kotlin_Examples PreCommit'
diff --git a/.github/workflows/beam_PreCommit_Portable_Python.yml 
b/.github/workflows/beam_PreCommit_Portable_Python.yml
index bfc6c2fcb1c..7b11fc18faf 100644
--- a/.github/workflows/beam_PreCommit_Portable_Python.yml
+++ b/.github/workflows/beam_PreCommit_Portable_Python.yml
@@ -28,7 +28,7 @@ on:
       - 'sdks/python/**'
       - 'release/**'
       - '.github/workflows/beam_PreCommit_Portable_Python.yml'
-  pull_request_target:
+  pull_request:
     branches: ['master', 'release-*']
     paths:
       - 'model/**'
@@ -46,7 +46,7 @@ on:
     - cron: '30 2/6 * * *'
   workflow_dispatch:
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: read
@@ -85,7 +85,7 @@ jobs:
         python_version: ['3.10', '3.14']
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       github.event_name == 'workflow_dispatch' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       startsWith(github.event.comment.body, 'Run Portable_Python PreCommit')
diff --git a/.github/workflows/beam_PreCommit_Prism_Python.yml 
b/.github/workflows/beam_PreCommit_Prism_Python.yml
index 8a5e2b6433b..c4838d2a395 100644
--- a/.github/workflows/beam_PreCommit_Prism_Python.yml
+++ b/.github/workflows/beam_PreCommit_Prism_Python.yml
@@ -25,7 +25,7 @@ on:
       - 'sdks/python/**'
       - 'release/**'
       - '.github/workflows/beam_PreCommit_Prism_Python.yml'
-  pull_request_target:
+  pull_request:
     branches: ['master', 'release-*']
     paths:
       - 'model/**'
@@ -40,7 +40,7 @@ on:
     - cron: '30 2/6 * * *'
   workflow_dispatch:
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: read
@@ -79,7 +79,7 @@ jobs:
         python_version: ['3.10', '3.14']
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       github.event_name == 'workflow_dispatch' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       startsWith(github.event.comment.body, 'Run Prism_Python PreCommit')
diff --git a/.github/workflows/beam_PreCommit_PythonDocker.yml 
b/.github/workflows/beam_PreCommit_PythonDocker.yml
index fd057b64054..fd19fd2a9ab 100644
--- a/.github/workflows/beam_PreCommit_PythonDocker.yml
+++ b/.github/workflows/beam_PreCommit_PythonDocker.yml
@@ -15,7 +15,7 @@
 
 name: PreCommit Python Docker
 on:
-  pull_request_target:
+  pull_request:
     branches: [ "master", "release-*" ]
     paths: [ "model/**","sdks/python/**","release/**", 
'release/trigger_all_tests.json', 
'.github/trigger_files/beam_PreCommit_PythonDocker.json']
   push:
@@ -26,7 +26,7 @@ on:
     - cron: '0 3/6 * * *'
   workflow_dispatch:
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: read
@@ -65,7 +65,7 @@ jobs:
         python_version: ['3.10','3.11','3.12','3.13','3.14']
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       github.event_name == 'workflow_dispatch' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam')
     steps:
diff --git a/.github/workflows/beam_PreCommit_PythonDocs.yml 
b/.github/workflows/beam_PreCommit_PythonDocs.yml
index 1a32212705d..96eca7afd63 100644
--- a/.github/workflows/beam_PreCommit_PythonDocs.yml
+++ b/.github/workflows/beam_PreCommit_PythonDocs.yml
@@ -16,7 +16,7 @@
 name: PreCommit Python Docs
 
 on:
-  pull_request_target:
+  pull_request:
     branches: [ "master", "release-*" ]
     paths: ["sdks/python/**", 'release/trigger_all_tests.json', 
'.github/trigger_files/beam_PreCommit_PythonDocs.json']
   issue_comment:
@@ -29,7 +29,7 @@ on:
     - cron: '0 3/6 * * *'
   workflow_dispatch:
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: read
@@ -66,7 +66,7 @@ jobs:
     timeout-minutes: 30
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event_name == 'workflow_dispatch' ||
       github.event.comment.body == 'Run PythonDocs PreCommit'
diff --git a/.github/workflows/beam_PreCommit_PythonFormatter.yml 
b/.github/workflows/beam_PreCommit_PythonFormatter.yml
index 5b052d9376a..18b2c444298 100644
--- a/.github/workflows/beam_PreCommit_PythonFormatter.yml
+++ b/.github/workflows/beam_PreCommit_PythonFormatter.yml
@@ -15,7 +15,7 @@
 
 name: PreCommit Python Formatter
 on:
-  pull_request_target:
+  pull_request:
     branches: [ "master", "release-*" ]
     paths: [ "sdks/python/apache_beam/**", 'release/trigger_all_tests.json', 
'.github/trigger_files/beam_PreCommit_PythonFormatter.json']
   issue_comment:
@@ -28,7 +28,7 @@ on:
     - cron: '0 3/6 * * *'
   workflow_dispatch:
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: read
@@ -65,7 +65,7 @@ jobs:
     timeout-minutes: 120
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event_name == 'workflow_dispatch' ||
       github.event.comment.body == 'Run PythonFormatter PreCommit'
diff --git a/.github/workflows/beam_PreCommit_PythonLint.yml 
b/.github/workflows/beam_PreCommit_PythonLint.yml
index 637470db711..033fe2cdf4b 100644
--- a/.github/workflows/beam_PreCommit_PythonLint.yml
+++ b/.github/workflows/beam_PreCommit_PythonLint.yml
@@ -15,7 +15,7 @@
 
 name: PreCommit Python Lint
 on:
-  pull_request_target:
+  pull_request:
     branches: [ "master", "release-*" ]
     paths: ["sdks/python/**","release/**", 'release/trigger_all_tests.json', 
'.github/trigger_files/beam_PreCommit_PythonLint.json']
   issue_comment:
@@ -28,7 +28,7 @@ on:
     - cron: '0 3/6 * * *'
   workflow_dispatch:
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: read
@@ -65,7 +65,7 @@ jobs:
     timeout-minutes: 120
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event_name == 'workflow_dispatch' ||
       github.event.comment.body == 'Run PythonLint PreCommit'
diff --git a/.github/workflows/beam_PreCommit_Python_Dataframes.yml 
b/.github/workflows/beam_PreCommit_Python_Dataframes.yml
index 95515c72964..8a71a0cf19a 100644
--- a/.github/workflows/beam_PreCommit_Python_Dataframes.yml
+++ b/.github/workflows/beam_PreCommit_Python_Dataframes.yml
@@ -15,7 +15,7 @@
 
 name: PreCommit Python Dataframes
 on:
-  pull_request_target:
+  pull_request:
     branches: [ "master", "release-*" ]
     paths: [ "model/**","sdks/python/**","release/**", 
'release/trigger_all_tests.json', 
'.github/trigger_files/beam_PreCommit_Python_Dataframes.json']
   issue_comment:
@@ -28,7 +28,7 @@ on:
     - cron: '45 2/6 * * *'
   workflow_dispatch:
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: write
@@ -67,7 +67,7 @@ jobs:
         python_version: ['3.10','3.14']
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event_name == 'workflow_dispatch' ||
       startsWith(github.event.comment.body, 'Run Python_Dataframes PreCommit')
@@ -111,5 +111,6 @@ jobs:
         with:
           commit: '${{ env.prsha || env.GITHUB_SHA }}'
           comment_mode: ${{ github.event_name == 'issue_comment'  && 'always' 
|| 'off' }}
+          check_run: ${{ github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository }}
           files: '**/pytest*.xml'
           large_files: true
diff --git a/.github/workflows/beam_PreCommit_Python_Dill.yml 
b/.github/workflows/beam_PreCommit_Python_Dill.yml
index f5f7c937bed..9f6a1e5ef32 100644
--- a/.github/workflows/beam_PreCommit_Python_Dill.yml
+++ b/.github/workflows/beam_PreCommit_Python_Dill.yml
@@ -15,7 +15,7 @@
 
 name: PreCommit Python Dill tests with dill deps installed
 on:
-  pull_request_target:
+  pull_request:
     branches: [ "master", "release-*" ]
     # paths: [ "model/**","sdks/python/**","release/**", 
'release/trigger_all_tests.json', 
'.github/trigger_files/beam_PreCommit_Python_Dill.json']    
     paths: [ '.github/trigger_files/beam_PreCommit_Python_Dill.json', 
'release/trigger_all_tests.json']
@@ -30,7 +30,7 @@ on:
     - cron: '45 2/6 * * *'
   workflow_dispatch:
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: write
@@ -76,7 +76,7 @@ jobs:
         os: [[self-hosted, ubuntu-24.04, main]]
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event_name == 'workflow_dispatch' ||
       startsWith(github.event.comment.body, 'Run Python_Dill PreCommit')
diff --git a/.github/workflows/beam_PreCommit_Python_Integration.yml 
b/.github/workflows/beam_PreCommit_Python_Integration.yml
index 0aa813a673d..63021886a72 100644
--- a/.github/workflows/beam_PreCommit_Python_Integration.yml
+++ b/.github/workflows/beam_PreCommit_Python_Integration.yml
@@ -15,7 +15,7 @@
 
 name: PreCommit Python Integration
 on:
-  pull_request_target:
+  pull_request:
     branches: [ "master", "release-*" ]
     paths: ["model/**", "sdks/python/**", "release/**", 
'release/trigger_all_tests.json', 
'.github/trigger_files/beam_PreCommit_Python_Integration.json']
   issue_comment:
@@ -28,7 +28,7 @@ on:
     - cron: '45 2/6 * * *'
   workflow_dispatch:
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: write
@@ -67,7 +67,7 @@ jobs:
         python_version: ['3.10', '3.14']
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event_name == 'workflow_dispatch' ||
       startsWith(github.event.comment.body, 'Run Python_Integration PreCommit')
@@ -118,5 +118,6 @@ jobs:
         with:
           commit: '${{ env.prsha || env.GITHUB_SHA }}'
           comment_mode: ${{ github.event_name == 'issue_comment'  && 'always' 
|| 'off' }}
+          check_run: ${{ github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository }}
           files: '**/pytest*.xml'
           large_files: true
diff --git a/.github/workflows/beam_PreCommit_Python_PVR_Flink.yml 
b/.github/workflows/beam_PreCommit_Python_PVR_Flink.yml
index 3b4b6acf733..876693068e7 100644
--- a/.github/workflows/beam_PreCommit_Python_PVR_Flink.yml
+++ b/.github/workflows/beam_PreCommit_Python_PVR_Flink.yml
@@ -16,7 +16,7 @@
 name: PreCommit Python PVR Flink
 
 on:
-  pull_request_target:
+  pull_request:
     branches: ['master', 'release-*']
     paths:
       - 'model/**'
@@ -48,7 +48,7 @@ on:
     - cron: '45 2/6 * * *'
   workflow_dispatch:
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: write
@@ -84,7 +84,7 @@ jobs:
     timeout-minutes: 120
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event_name == 'workflow_dispatch' ||
       github.event.comment.body == 'Run Python_PVR_Flink PreCommit'
@@ -124,5 +124,6 @@ jobs:
         with:
           commit: '${{ env.prsha || env.GITHUB_SHA }}'
           comment_mode: ${{ github.event_name == 'issue_comment'  && 'always' 
|| 'off' }}
+          check_run: ${{ github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository }}
           files: '**/pytest*.xml'
           large_files: true
diff --git a/.github/workflows/beam_PreCommit_Python_Runners.yml 
b/.github/workflows/beam_PreCommit_Python_Runners.yml
index c04c7736c5f..b16de16a864 100644
--- a/.github/workflows/beam_PreCommit_Python_Runners.yml
+++ b/.github/workflows/beam_PreCommit_Python_Runners.yml
@@ -15,7 +15,7 @@
 
 name: PreCommit Python Runners
 on:
-  pull_request_target:
+  pull_request:
     branches: [ "master", "release-*" ]
     paths: [ "model/**","sdks/python/**","release/**", 
'release/trigger_all_tests.json', 
'.github/trigger_files/beam_PreCommit_Python_Runners.json']
   issue_comment:
@@ -28,7 +28,7 @@ on:
     - cron: '45 2/6 * * *'
   workflow_dispatch:
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: write
@@ -67,7 +67,7 @@ jobs:
         python_version: ['3.10','3.14']
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event_name == 'workflow_dispatch' ||
       startsWith(github.event.comment.body, 'Run Python_Runners PreCommit')
@@ -111,5 +111,6 @@ jobs:
         with:
           commit: '${{ env.prsha || env.GITHUB_SHA }}'
           comment_mode: ${{ github.event_name == 'issue_comment'  && 'always' 
|| 'off' }}
+          check_run: ${{ github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository }}
           files: '**/pytest*.xml'
           large_files: true
diff --git a/.github/workflows/beam_PreCommit_SQL.yml 
b/.github/workflows/beam_PreCommit_SQL.yml
index 339cc016c63..5842d89fc41 100644
--- a/.github/workflows/beam_PreCommit_SQL.yml
+++ b/.github/workflows/beam_PreCommit_SQL.yml
@@ -20,7 +20,7 @@ on:
     tags: ['v*']
     branches: ['master', 'release-*']
     paths: 
['sdks/java/extensions/sql/**','.github/workflows/beam_PreCommit_SQL.yml']
-  pull_request_target:
+  pull_request:
     branches: ['master', 'release-*']
     paths: ['sdks/java/extensions/sql/**', 'release/trigger_all_tests.json', 
'.github/trigger_files/beam_PreCommit_SQL.json']
   issue_comment:
@@ -34,7 +34,7 @@ concurrency:
   group: '${{ github.workflow }} @ ${{ github.event.pull_request.number || 
github.event.pull_request.head.label || github.sha || github.head_ref || 
github.ref }}-${{ github.event.schedule || github.event.comment.id || 
github.event.sender.login }}'
   cancel-in-progress: true
 
-# Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: write
@@ -66,7 +66,7 @@ jobs:
     timeout-minutes: 120
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event_name == 'workflow_dispatch' ||
       github.event.comment.body == 'Run SQL PreCommit'
@@ -104,6 +104,7 @@ jobs:
         with:
           commit: '${{ env.prsha || env.GITHUB_SHA }}'
           comment_mode: ${{ github.event_name == 'issue_comment'  && 'always' 
|| 'off' }}
+          check_run: ${{ github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository }}
           files: '**/build/test-results/**/*.xml'
           large_files: true
       - name: Archive SpotBugs Results
@@ -114,7 +115,7 @@ jobs:
           path: '**/build/reports/spotbugs/*.html'
       - name: Publish SpotBugs Results
         uses: jwgmeligmeyling/[email protected]
-        if: always()
+        if: always() && (github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository)
         with:
           name: Publish SpotBugs
           path: '**/build/reports/spotbugs/*.html'
diff --git a/.github/workflows/beam_PreCommit_SQL_Java17.yml 
b/.github/workflows/beam_PreCommit_SQL_Java17.yml
index 48822a1404f..a842b1794a4 100644
--- a/.github/workflows/beam_PreCommit_SQL_Java17.yml
+++ b/.github/workflows/beam_PreCommit_SQL_Java17.yml
@@ -20,7 +20,7 @@ on:
     tags: ['v*']
     branches: ['master', 'release-*']
     paths: 
['sdks/java/extensions/sql/**','.github/workflows/beam_PreCommit_SQL_Java17.yml']
-  pull_request_target:
+  pull_request:
     branches: ['master', 'release-*']
     paths: ['sdks/java/extensions/sql/**', 'release/trigger_all_tests.json', 
'.github/trigger_files/beam_PreCommit_SQL_Java17.json']
   issue_comment:
@@ -29,7 +29,7 @@ on:
     - cron: '15 3/6 * * *'
   workflow_dispatch:
 
-# Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: write
@@ -65,7 +65,7 @@ jobs:
     timeout-minutes: 120
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event_name == 'workflow_dispatch' ||
       github.event.comment.body == 'Run SQL_Java17 PreCommit'
@@ -111,6 +111,7 @@ jobs:
         with:
           commit: '${{ env.prsha || env.GITHUB_SHA }}'
           comment_mode: ${{ github.event_name == 'issue_comment'  && 'always' 
|| 'off' }}
+          check_run: ${{ github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository }}
           files: '**/build/test-results/**/*.xml'
           large_files: true
       - name: Archive SpotBugs Results
@@ -121,7 +122,7 @@ jobs:
           path: '**/build/reports/spotbugs/*.html'
       - name: Publish SpotBugs Results
         uses: jwgmeligmeyling/[email protected]
-        if: always()
+        if: always() && (github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository)
         with:
           name: Publish SpotBugs
           path: '**/build/reports/spotbugs/*.html'
diff --git a/.github/workflows/beam_PreCommit_Spotless.yml 
b/.github/workflows/beam_PreCommit_Spotless.yml
index 003d5754a7d..1875256679b 100644
--- a/.github/workflows/beam_PreCommit_Spotless.yml
+++ b/.github/workflows/beam_PreCommit_Spotless.yml
@@ -15,7 +15,7 @@
 name: PreCommit Spotless
 
 on:
-  pull_request_target:
+  pull_request:
     branches: ['master', 'release-*']
     paths:
       - 'buildSrc/**'
@@ -38,7 +38,7 @@ concurrency:
   group: '${{ github.workflow }} @ ${{ github.event.pull_request.number || 
github.event.pull_request.head.label || github.sha || github.head_ref || 
github.ref }}-${{ github.event.schedule || github.event.comment.id || 
github.event.sender.login }}'
   cancel-in-progress: true
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: read
@@ -71,7 +71,7 @@ jobs:
         job_phrase: [Run Spotless PreCommit]
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event_name == 'workflow_dispatch' ||
       github.event.comment.body == 'Run Spotless PreCommit'
diff --git a/.github/workflows/beam_PreCommit_Typescript.yml 
b/.github/workflows/beam_PreCommit_Typescript.yml
index 4fef4386e81..4f94960fcf7 100644
--- a/.github/workflows/beam_PreCommit_Typescript.yml
+++ b/.github/workflows/beam_PreCommit_Typescript.yml
@@ -22,7 +22,7 @@ on:
     tags: ['v*']
     branches: ['master', 'release-*']
     paths: ['sdks/python/apache_beam/runners/interactive/extensions/**', 
'.github/workflows/beam_PreCommit_Typescript.yml']
-  pull_request_target:
+  pull_request:
     branches: ['master', 'release-*']
     paths: ['sdks/python/apache_beam/runners/interactive/extensions/**', 
'release/trigger_all_tests.json', 
'.github/trigger_files/beam_PreCommit_Typescript.json']
   issue_comment:
@@ -41,7 +41,7 @@ env:
   GRADLE_ENTERPRISE_CACHE_USERNAME: ${{ secrets.GE_CACHE_USERNAME }}
   GRADLE_ENTERPRISE_CACHE_PASSWORD: ${{ secrets.GE_CACHE_PASSWORD }}
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: read
@@ -67,7 +67,7 @@ jobs:
         job_phrase: [Run Typescript PreCommit]
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event_name == 'workflow_dispatch' ||
       github.event.comment.body == 'Run Typescript PreCommit'
diff --git a/.github/workflows/beam_PreCommit_Website.yml 
b/.github/workflows/beam_PreCommit_Website.yml
index c8fb8713074..c19a139a30e 100644
--- a/.github/workflows/beam_PreCommit_Website.yml
+++ b/.github/workflows/beam_PreCommit_Website.yml
@@ -20,7 +20,7 @@ on:
     tags: ['v*']
     branches: ['master', 'release-*']
     paths: ['website/**','.github/workflows/beam_PreCommit_Website.yml']
-  pull_request_target:
+  pull_request:
     branches: ['master', 'release-*']
     paths: ['website/**', 'release/trigger_all_tests.json', 
'.github/trigger_files/beam_PreCommit_Website.json']
   issue_comment:
@@ -29,7 +29,7 @@ on:
     - cron: '15 3/6 * * *'
   workflow_dispatch:
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: read
@@ -66,7 +66,7 @@ jobs:
     timeout-minutes: 120
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event_name == 'workflow_dispatch' ||
       github.event.comment.body == 'Run Website PreCommit'
diff --git a/.github/workflows/beam_PreCommit_Whitespace.yml 
b/.github/workflows/beam_PreCommit_Whitespace.yml
index 6b95073dc3a..48ffbe02b83 100644
--- a/.github/workflows/beam_PreCommit_Whitespace.yml
+++ b/.github/workflows/beam_PreCommit_Whitespace.yml
@@ -20,7 +20,7 @@ on:
     tags: ['v*']
     branches: ['master', 'release-*']
     paths: ['**.md', '**.gradle', '**.kts', 
'.github/workflows/beam_PreCommit_Whitespace.yml']
-  pull_request_target:
+  pull_request:
     branches: ['master', 'release-*']
     paths: ['**.md', '**.gradle', '**.kts', 'release/trigger_all_tests.json', 
'.github/trigger_files/beam_PreCommit_Whitespace.json']
   issue_comment:
@@ -65,7 +65,7 @@ jobs:
     timeout-minutes: 120
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event_name == 'workflow_dispatch' ||
       github.event.comment.body == 'Run Whitespace PreCommit'
diff --git a/.github/workflows/beam_PreCommit_Xlang_Generated_Transforms.yml 
b/.github/workflows/beam_PreCommit_Xlang_Generated_Transforms.yml
index fa94a2b1320..09f567d657c 100644
--- a/.github/workflows/beam_PreCommit_Xlang_Generated_Transforms.yml
+++ b/.github/workflows/beam_PreCommit_Xlang_Generated_Transforms.yml
@@ -29,7 +29,7 @@ on:
       - 'sdks/java/extensions/sql/**'
       - 'release/**'
       - '.github/workflows/beam_PreCommit_Xlang_Generated_Transforms.yml'
-  pull_request_target:
+  pull_request:
     branches: ['master', 'release-*']
     paths:
       - 'model/**'
@@ -48,7 +48,7 @@ on:
     - cron: '30 2/6 * * *'
   workflow_dispatch:
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: read
@@ -88,7 +88,7 @@ jobs:
     if: |
       github.event_name == 'push' ||
       github.event_name == 'workflow_dispatch' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       startsWith(github.event.comment.body, 'Run Xlang_Generated_Transforms 
PreCommit')
     steps:
diff --git a/.github/workflows/beam_PreCommit_Yaml_Xlang_Direct.yml 
b/.github/workflows/beam_PreCommit_Yaml_Xlang_Direct.yml
index d92783c5318..8b877671df2 100644
--- a/.github/workflows/beam_PreCommit_Yaml_Xlang_Direct.yml
+++ b/.github/workflows/beam_PreCommit_Yaml_Xlang_Direct.yml
@@ -16,7 +16,7 @@
 name: PreCommit YAML Xlang Direct
 
 on:
-  pull_request_target:
+  pull_request:
     paths: ['release/trigger_all_tests.json', 'model/**', 'sdks/python/**', 
'.github/trigger_files/beam_PreCommit_Yaml_Xlang_Direct.json']
   issue_comment:
     types: [created]
@@ -36,7 +36,7 @@ on:
     - cron: '30 5/6 * * *'
   workflow_dispatch:
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: write
@@ -67,7 +67,7 @@ jobs:
     if: |
       github.event_name == 'push' ||
       github.event_name == 'workflow_dispatch' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event.comment.body == 'Run Yaml_Xlang_Direct PreCommit'
     runs-on: [self-hosted, ubuntu-24.04, main]
@@ -108,5 +108,6 @@ jobs:
         with:
           commit: '${{ env.prsha || env.GITHUB_SHA }}'
           comment_mode: ${{ github.event_name == 'issue_comment'  && 'always' 
|| 'off' }}
+          check_run: ${{ github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository }}
           files: '**/pytest*.xml'
           large_files: true

Reply via email to