From bf6ea21b32a0f92de24a5e4c327a5e703ac7f708 Mon Sep 17 00:00:00 2001 From: Guido X Jansen Date: Wed, 4 Mar 2026 20:24:26 +0100 Subject: [PATCH] fix(ci): use pull_request_target for Dependabot secret access (#137) Dependabot PRs don't receive repo secrets under pull_request events, causing DEPLOY_PAT to be empty. Switch to pull_request_target which runs in the base branch context with full secret access. Safe because the workflow only runs for dependabot[bot] and only executes pnpm install -- no PR-supplied code is run. --- .github/workflows/fix-lockfile.yml | 9 +++++++-- 1 file changed, 7 insertions(+), 2 deletions(-) diff --git a/.github/workflows/fix-lockfile.yml b/.github/workflows/fix-lockfile.yml index 0c19844..978a9b4 100644 --- a/.github/workflows/fix-lockfile.yml +++ b/.github/workflows/fix-lockfile.yml @@ -4,9 +4,14 @@ name: Fix Lockfile # catalog: specifiers to concrete versions in the lockfile, causing # a mismatch that fails `pnpm install --frozen-lockfile` in CI. # This workflow regenerates the lockfile on Dependabot PRs. +# +# Uses pull_request_target so the workflow has access to repo secrets +# (Dependabot PRs don't get secrets with plain pull_request). +# Safe because: only runs for dependabot[bot], only executes pnpm install +# (no PR-supplied scripts), and only commits pnpm-lock.yaml. on: - pull_request: + pull_request_target: paths: - 'package.json' - 'pnpm-lock.yaml' @@ -25,7 +30,7 @@ jobs: steps: - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 with: - ref: ${{ github.head_ref }} + ref: ${{ github.event.pull_request.head.ref }} token: ${{ secrets.DEPLOY_PAT }} - uses: pnpm/action-setup@a7487c7e89a18df4991f7f222e4898a00d66ddda # v4.1.0 -- 2.51.2