This is an automated email from the ASF dual-hosted git repository.

damccorm pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/beam.git


The following commit(s) were added to refs/heads/master by this push:
     new 4a8296292d1 Migrate secret-using workflows from pull_request_target to 
pull_request (#40375)
4a8296292d1 is described below

commit 4a8296292d134aba9f1d795c0d200d6014425fd8
Author: Danny McCormick <[email protected]>
AuthorDate: Fri Oct 2 10:17:43 2026 +0000

    Migrate secret-using workflows from pull_request_target to pull_request 
(#40375)
---
 .github/workflows/beam_CloudML_Benchmarks_Dataflow.yml     |  5 +++--
 .github/workflows/beam_Java_JMH.yml                        |  6 +++---
 .../workflows/beam_PostCommit_Java_Nexmark_Dataflow.yml    |  6 +++---
 .../workflows/beam_PostCommit_Java_Nexmark_Dataflow_V2.yml |  6 +++---
 .../beam_PostCommit_Java_Nexmark_Dataflow_V2_Java.yml      |  6 +++---
 .github/workflows/beam_PostCommit_Java_Nexmark_Direct.yml  |  6 +++---
 .github/workflows/beam_PostCommit_Java_Nexmark_Flink.yml   |  6 +++---
 .github/workflows/beam_PostCommit_Java_Nexmark_Spark.yml   |  6 +++---
 .github/workflows/beam_PostCommit_Java_Tpcds_Dataflow.yml  |  6 +++---
 .github/workflows/beam_PostCommit_Java_Tpcds_Flink.yml     |  6 +++---
 .github/workflows/beam_PostCommit_Java_Tpcds_Spark.yml     |  6 +++---
 .github/workflows/beam_PostCommit_Python_Dependency.yml    |  7 ++++---
 .github/workflows/beam_PreCommit_Flink_Container.yml       | 14 +++++++-------
 .github/workflows/beam_PreCommit_Python_Coverage.yml       |  7 ++++---
 14 files changed, 48 insertions(+), 45 deletions(-)

diff --git a/.github/workflows/beam_CloudML_Benchmarks_Dataflow.yml 
b/.github/workflows/beam_CloudML_Benchmarks_Dataflow.yml
index 1a7747cfc2f..435c844bf92 100644
--- a/.github/workflows/beam_CloudML_Benchmarks_Dataflow.yml
+++ b/.github/workflows/beam_CloudML_Benchmarks_Dataflow.yml
@@ -18,11 +18,11 @@ name: CloudML Benchmarks Dataflow
 on:
   schedule:
     - cron: '10 21 * * *'
-  pull_request_target:
+  pull_request:
     paths: ['release/trigger_all_tests.json', 
'.github/trigger_files/beam_CloudML_Benchmarks_Dataflow.json']
   workflow_dispatch:
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: read
@@ -54,6 +54,7 @@ jobs:
   beam_CloudML_Benchmarks_Dataflow:
     if: |
       github.event_name == 'workflow_dispatch' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam')
     runs-on: [self-hosted, ubuntu-24.04, main]
     timeout-minutes: 360
diff --git a/.github/workflows/beam_Java_JMH.yml 
b/.github/workflows/beam_Java_JMH.yml
index cd20a3c9e1e..77a10ee66bd 100644
--- a/.github/workflows/beam_Java_JMH.yml
+++ b/.github/workflows/beam_Java_JMH.yml
@@ -18,11 +18,11 @@ name: Java JMH
 on:
   schedule:
     - cron: '0 0 * * 0'
-  pull_request_target:
+  pull_request:
     paths: ['release/trigger_all_tests.json', 
'.github/trigger_files/beam_Java_JMH.json']
   workflow_dispatch:
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: read
@@ -56,7 +56,7 @@ jobs:
   beam_Java_JMH:
     if: |
       github.event_name == 'workflow_dispatch' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam')
     runs-on: [self-hosted, ubuntu-24.04, main]
     timeout-minutes: 900
diff --git a/.github/workflows/beam_PostCommit_Java_Nexmark_Dataflow.yml 
b/.github/workflows/beam_PostCommit_Java_Nexmark_Dataflow.yml
index a88281151e5..9c8a1f111f2 100644
--- a/.github/workflows/beam_PostCommit_Java_Nexmark_Dataflow.yml
+++ b/.github/workflows/beam_PostCommit_Java_Nexmark_Dataflow.yml
@@ -20,7 +20,7 @@ name: PostCommit Java Nexmark Dataflow
 on:
   schedule:
     - cron: '15 4/6 * * *'
-  pull_request_target:
+  pull_request:
     paths: ['release/trigger_all_tests.json', 
'.github/trigger_files/beam_PostCommit_Java_Nexmark_Dataflow.json']
   workflow_dispatch:
 
@@ -29,7 +29,7 @@ concurrency:
   group: '${{ github.workflow }} @ ${{ github.event.pull_request.number || 
github.sha || github.head_ref || github.ref }}-${{ github.event.schedule || 
github.event.comment.id || github.event.sender.login }}'
   cancel-in-progress: true
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: write
@@ -89,7 +89,7 @@ jobs:
         queryLanguage: [sql, none]
     if: |
       github.event_name == 'workflow_dispatch' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event.comment.body == 'Run Dataflow Runner Nexmark Tests'
     steps:
diff --git a/.github/workflows/beam_PostCommit_Java_Nexmark_Dataflow_V2.yml 
b/.github/workflows/beam_PostCommit_Java_Nexmark_Dataflow_V2.yml
index ba00e5cf8cb..fdf7ceb4fc9 100644
--- a/.github/workflows/beam_PostCommit_Java_Nexmark_Dataflow_V2.yml
+++ b/.github/workflows/beam_PostCommit_Java_Nexmark_Dataflow_V2.yml
@@ -20,7 +20,7 @@ name: PostCommit Java Nexmark Dataflow V2
 on:
   schedule:
     - cron: '15 4/6 * * *'
-  pull_request_target:
+  pull_request:
     paths: ['release/trigger_all_tests.json', 
'.github/trigger_files/beam_PostCommit_Java_Nexmark_Dataflow_V2.json']
   workflow_dispatch:
 
@@ -29,7 +29,7 @@ concurrency:
   group: '${{ github.workflow }} @ ${{ github.event.pull_request.number || 
github.sha || github.head_ref || github.ref }}-${{ github.event.schedule || 
github.event.comment.id || github.event.sender.login }}'
   cancel-in-progress: true
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: write
@@ -89,7 +89,7 @@ jobs:
         streaming: [false, true]
     if: |
       github.event_name == 'workflow_dispatch' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event.comment.body == 'Run Dataflow Runner V2 Nexmark Tests'
     steps:
diff --git 
a/.github/workflows/beam_PostCommit_Java_Nexmark_Dataflow_V2_Java.yml 
b/.github/workflows/beam_PostCommit_Java_Nexmark_Dataflow_V2_Java.yml
index a3410e4acc0..998bfae0c43 100644
--- a/.github/workflows/beam_PostCommit_Java_Nexmark_Dataflow_V2_Java.yml
+++ b/.github/workflows/beam_PostCommit_Java_Nexmark_Dataflow_V2_Java.yml
@@ -20,7 +20,7 @@ name: PostCommit Java Nexmark Dataflow V2 Java
 on:
   schedule:
     - cron: '0 4/6 * * *'
-  pull_request_target:
+  pull_request:
     paths: ['release/trigger_all_tests.json', 
'.github/trigger_files/beam_PostCommit_Java_Nexmark_Dataflow_V2_Java.json']
   workflow_dispatch:
 
@@ -29,7 +29,7 @@ concurrency:
   group: '${{ github.workflow }} @ ${{ github.event.pull_request.number || 
github.sha || github.head_ref || github.ref }}-${{ github.event.schedule || 
github.event.comment.id || github.event.sender.login }}'
   cancel-in-progress: true
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: write
@@ -90,7 +90,7 @@ jobs:
         java_version: ['11','17']
     if: |
       github.event_name == 'workflow_dispatch' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       (contains(github.event.comment.body, 'Run Dataflow Runner V2 Java') &&
          contains(github.event.comment.body, 'Nexmark Tests'))
diff --git a/.github/workflows/beam_PostCommit_Java_Nexmark_Direct.yml 
b/.github/workflows/beam_PostCommit_Java_Nexmark_Direct.yml
index aa87c809038..337c3889a99 100644
--- a/.github/workflows/beam_PostCommit_Java_Nexmark_Direct.yml
+++ b/.github/workflows/beam_PostCommit_Java_Nexmark_Direct.yml
@@ -20,7 +20,7 @@ name: PostCommit Java Nexmark Direct
 on:
   schedule:
     - cron: '15 4/6 * * *'
-  pull_request_target:
+  pull_request:
     paths: ['release/trigger_all_tests.json', 
'.github/trigger_files/beam_PostCommit_Java_Nexmark_Direct.json']
   workflow_dispatch:
 
@@ -29,7 +29,7 @@ concurrency:
   group: '${{ github.workflow }} @ ${{ github.event.pull_request.number || 
github.sha || github.head_ref || github.ref }}-${{ github.event.schedule || 
github.event.comment.id || github.event.sender.login }}'
   cancel-in-progress: true
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: write
@@ -84,7 +84,7 @@ jobs:
         queryLanguage: [sql, none]
     if: |
       github.event_name == 'workflow_dispatch' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event.comment.body == 'Run Direct Runner Nexmark Tests'
     steps:
diff --git a/.github/workflows/beam_PostCommit_Java_Nexmark_Flink.yml 
b/.github/workflows/beam_PostCommit_Java_Nexmark_Flink.yml
index 11d015633db..4543419bdcd 100644
--- a/.github/workflows/beam_PostCommit_Java_Nexmark_Flink.yml
+++ b/.github/workflows/beam_PostCommit_Java_Nexmark_Flink.yml
@@ -20,7 +20,7 @@ name: PostCommit Java Nexmark Flink
 on:
   schedule:
     - cron: '15 4/6 * * *'
-  pull_request_target:
+  pull_request:
     paths: ['release/trigger_all_tests.json', 
'.github/trigger_files/beam_PostCommit_Java_Nexmark_Flink.json']
   workflow_dispatch:
 
@@ -29,7 +29,7 @@ concurrency:
   group: '${{ github.workflow }} @ ${{ github.event.pull_request.number || 
github.sha || github.head_ref || github.ref }}-${{ github.event.schedule || 
github.event.comment.id || github.event.sender.login }}'
   cancel-in-progress: true
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: write
@@ -83,7 +83,7 @@ jobs:
         queryLanguage: [sql, none]
     if: |
       github.event_name == 'workflow_dispatch' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event.comment.body == 'Run Flink Runner Nexmark Tests'
     steps:
diff --git a/.github/workflows/beam_PostCommit_Java_Nexmark_Spark.yml 
b/.github/workflows/beam_PostCommit_Java_Nexmark_Spark.yml
index ea18aad79c3..9f49da70014 100644
--- a/.github/workflows/beam_PostCommit_Java_Nexmark_Spark.yml
+++ b/.github/workflows/beam_PostCommit_Java_Nexmark_Spark.yml
@@ -20,7 +20,7 @@ name: PostCommit Java Nexmark Spark
 on:
   schedule:
     - cron: '15 4/6 * * *'
-  pull_request_target:
+  pull_request:
     paths: ['release/trigger_all_tests.json', 
'.github/trigger_files/beam_PostCommit_Java_Nexmark_Spark.json']
   workflow_dispatch:
 
@@ -29,7 +29,7 @@ concurrency:
   group: '${{ github.workflow }} @ ${{ github.event.pull_request.number || 
github.sha || github.head_ref || github.ref }}-${{ github.event.schedule || 
github.event.comment.id || github.event.sender.login }}'
   cancel-in-progress: true
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: write
@@ -83,7 +83,7 @@ jobs:
         queryLanguage: [sql, none]
     if: |
       github.event_name == 'workflow_dispatch' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event.comment.body == 'Run Spark Runner Nexmark Tests'
     steps:
diff --git a/.github/workflows/beam_PostCommit_Java_Tpcds_Dataflow.yml 
b/.github/workflows/beam_PostCommit_Java_Tpcds_Dataflow.yml
index fb57bebdc51..5652dd2ffd8 100644
--- a/.github/workflows/beam_PostCommit_Java_Tpcds_Dataflow.yml
+++ b/.github/workflows/beam_PostCommit_Java_Tpcds_Dataflow.yml
@@ -18,11 +18,11 @@ name: PostCommit Java Tpcds Dataflow
 on:
   schedule:
     - cron: '30 4/6 * * *'
-  pull_request_target:
+  pull_request:
     paths: ['release/trigger_all_tests.json', 
'.github/trigger_files/beam_PostCommit_Java_Tpcds_Dataflow.json']
   workflow_dispatch:
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: read
@@ -79,7 +79,7 @@ jobs:
   beam_PostCommit_Java_Tpcds_Dataflow:
     if: |
       github.event_name == 'workflow_dispatch' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event.comment.body == 'Run Dataflow Runner Tpcds Tests'
     runs-on: [self-hosted, ubuntu-24.04, main]
diff --git a/.github/workflows/beam_PostCommit_Java_Tpcds_Flink.yml 
b/.github/workflows/beam_PostCommit_Java_Tpcds_Flink.yml
index 07d27555344..fdea72d4e84 100644
--- a/.github/workflows/beam_PostCommit_Java_Tpcds_Flink.yml
+++ b/.github/workflows/beam_PostCommit_Java_Tpcds_Flink.yml
@@ -18,11 +18,11 @@ name: PostCommit Java Tpcds Flink
 on:
   schedule:
     - cron: '30 4/6 * * *'
-  pull_request_target:
+  pull_request:
     paths: ['release/trigger_all_tests.json', 
'.github/trigger_files/beam_PostCommit_Java_Tpcds_Flink.json']
   workflow_dispatch:
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: read
@@ -76,7 +76,7 @@ jobs:
   beam_PostCommit_Java_Tpcds_Flink:
     if: |
       github.event_name == 'workflow_dispatch' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event.comment.body == 'Run Flink Runner Tpcds Tests'
     runs-on: [self-hosted, ubuntu-24.04, main]
diff --git a/.github/workflows/beam_PostCommit_Java_Tpcds_Spark.yml 
b/.github/workflows/beam_PostCommit_Java_Tpcds_Spark.yml
index 6b03a289015..83b2f089d36 100644
--- a/.github/workflows/beam_PostCommit_Java_Tpcds_Spark.yml
+++ b/.github/workflows/beam_PostCommit_Java_Tpcds_Spark.yml
@@ -18,11 +18,11 @@ name: PostCommit Java Tpcds Spark
 on:
   schedule:
     - cron: '30 4/6 * * *'
-  pull_request_target:
+  pull_request:
     paths: ['release/trigger_all_tests.json', 
'.github/trigger_files/beam_PostCommit_Java_Tpcds_Spark.json']
   workflow_dispatch:
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: read
@@ -74,7 +74,7 @@ jobs:
   beam_PostCommit_Java_Tpcds_Spark:
     if: |
       github.event_name == 'workflow_dispatch' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event.comment.body == 'Run Spark Runner Tpcds Tests'
     runs-on: [self-hosted, ubuntu-24.04, main]
diff --git a/.github/workflows/beam_PostCommit_Python_Dependency.yml 
b/.github/workflows/beam_PostCommit_Python_Dependency.yml
index ed10007829f..8835b1c8b5d 100644
--- a/.github/workflows/beam_PostCommit_Python_Dependency.yml
+++ b/.github/workflows/beam_PostCommit_Python_Dependency.yml
@@ -18,11 +18,11 @@ name: PostCommit Python Dependency
 on:
   schedule:
   - cron: '0 5/6 * * *'
-  pull_request_target:
+  pull_request:
     paths: ['release/trigger_all_tests.json', 
'.github/trigger_files/beam_PostCommit_Python_Dependency.json']
   workflow_dispatch:
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: write
@@ -63,7 +63,7 @@ jobs:
     timeout-minutes: 360
     if: |
       github.event_name == 'workflow_dispatch' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       startsWith(github.event.comment.body, 'Run Python PostCommit Dependency')
     steps:
@@ -106,5 +106,6 @@ jobs:
         with:
           commit: '${{ env.prsha || env.GITHUB_SHA }}'
           comment_mode: ${{ github.event_name == 'issue_comment'  && 'always' 
|| 'off' }}
+          check_run: ${{ github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository }}
           files: '**/pytest*.xml'
           large_files: true
diff --git a/.github/workflows/beam_PreCommit_Flink_Container.yml 
b/.github/workflows/beam_PreCommit_Flink_Container.yml
index 4ac77c21202..f131a058c54 100644
--- a/.github/workflows/beam_PreCommit_Flink_Container.yml
+++ b/.github/workflows/beam_PreCommit_Flink_Container.yml
@@ -16,7 +16,7 @@
 name: PreCommit Flink Container
 
 on:
-  pull_request_target:
+  pull_request:
     paths:
       - 'model/**'
       - 'sdks/python/apache_beam/runners/portability/**'
@@ -76,7 +76,7 @@ env:
   JOB_SERVER_IMAGE: 
gcr.io/apache-beam-testing/beam_portability/beam_flink_job_server:latest-flink2.2
   ARTIFACTS_DIR: gs://beam-flink-cluster/beam-precommit-flink-container-${{ 
github.run_id }}
   DOCKER_REGISTRY: gcr.io
-  DOCKER_REPOSITORY_ROOT: ${{ github.event_name == 'pull_request_target' && 
'gcr.io/apache-beam-testing/beam-sdk-pr' || 
'gcr.io/apache-beam-testing/beam-sdk' }}
+  DOCKER_REPOSITORY_ROOT: ${{ github.event_name == 'pull_request' && 
'gcr.io/apache-beam-testing/beam-sdk-pr' || 
'gcr.io/apache-beam-testing/beam-sdk' }}
   PYTHON_VERSION: '3.10'
   PYTHON_SDK_IMAGE_TAG: latest
 
@@ -86,7 +86,7 @@ jobs:
       github.event_name == 'workflow_dispatch' ||
       github.event_name == 'push' ||
       github.event_name == 'schedule' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       github.event.comment.body == 'Run Flink Container PreCommit'
     runs-on: [self-hosted, ubuntu-24.04, main]
     timeout-minutes: 90
@@ -110,14 +110,14 @@ jobs:
         with:
           python-version: default
       - name: GCloud Docker credential helper
-        if: ${{ github.event_name == 'pull_request_target' }}
+        if: ${{ github.event_name == 'pull_request' }}
         run: |
           gcloud auth configure-docker ${{ env.DOCKER_REGISTRY }}
       - name: Set PYTHON_SDK_IMAGE_TAG unique variable based on timestamp
-        if: ${{ github.event_name == 'pull_request_target' }}
+        if: ${{ github.event_name == 'pull_request' }}
         run: echo "PYTHON_SDK_IMAGE_TAG=$(date +'%Y%m%d-%H%M%S%N')" >> 
$GITHUB_ENV
       - name: Build and push to registry
-        if: ${{ github.event_name == 'pull_request_target' }}
+        if: ${{ github.event_name == 'pull_request' }}
         uses: ./.github/actions/gradle-command-self-hosted-action
         with:
           gradle-command: :sdks:python:container:py310:docker
@@ -182,6 +182,6 @@ jobs:
           ${{ github.workspace }}/.test-infra/dataproc/flink_cluster.sh delete
 
       - name: Cleanup Python SDK Container
-        if: ${{ always() && github.event_name == 'pull_request_target' }}
+        if: ${{ always() && github.event_name == 'pull_request' }}
         run: |
           gcloud container images delete 
${DOCKER_REPOSITORY_ROOT}/beam_python${{ env.PYTHON_VERSION }}_sdk:${{ 
env.PYTHON_SDK_IMAGE_TAG }} --force-delete-tags --quiet
diff --git a/.github/workflows/beam_PreCommit_Python_Coverage.yml 
b/.github/workflows/beam_PreCommit_Python_Coverage.yml
index 17bc17e33c1..f13fb9400ec 100644
--- a/.github/workflows/beam_PreCommit_Python_Coverage.yml
+++ b/.github/workflows/beam_PreCommit_Python_Coverage.yml
@@ -15,7 +15,7 @@
 
 name: PreCommit Python Coverage
 on:
-  pull_request_target:
+  pull_request:
     branches: [ "master", "release-*" ]
     paths: [ "model/**", "sdks/python/**", 
"sdks/go/pkg/beam/runners/prism/**", "release/**", 
'release/trigger_all_tests.json', 
'.github/trigger_files/beam_PreCommit_Python_Coverage.json']
   issue_comment:
@@ -28,7 +28,7 @@ on:
     - cron: '45 2/6 * * *'
   workflow_dispatch:
 
-#Setting explicit permissions for the action to avoid the default permissions 
which are `write-all` in case of pull_request_target event
+# Setting explicit permissions for the action
 permissions:
   actions: write
   pull-requests: write
@@ -69,7 +69,7 @@ jobs:
     timeout-minutes: 180
     if: |
       github.event_name == 'push' ||
-      github.event_name == 'pull_request_target' ||
+      github.event_name == 'pull_request' ||
       (github.event_name == 'schedule' && github.repository == 'apache/beam') 
||
       github.event_name == 'workflow_dispatch' ||
       startswith(github.event.comment.body, 'Run Python_Coverage PreCommit 3.')
@@ -116,6 +116,7 @@ jobs:
         with:
           commit: '${{ env.prsha || env.GITHUB_SHA }}'
           comment_mode: ${{ github.event_name == 'issue_comment'  && 'always' 
|| 'off' }}
+          check_run: ${{ github.event_name != 'pull_request' || 
github.event.pull_request.head.repo.full_name == github.repository }}
           files: '**/pytest*.xml'
           large_files: true
           check_name: "Python ${{ matrix.python_version }} Test Results (${{ 
join(matrix.os, ', ') }})"

Reply via email to