Use pull_request_target for better security with forked PRs (#22024)
This commit is contained in:
2
.github/workflows/automerge-dependencies.yml
vendored
2
.github/workflows/automerge-dependencies.yml
vendored
@@ -9,7 +9,7 @@ name: Auto Merge Dependency Updates
|
||||
# **Who does it impact**: It helps docs engineering focus on higher value work.
|
||||
|
||||
on:
|
||||
pull_request:
|
||||
pull_request_target:
|
||||
paths:
|
||||
- 'package*.json'
|
||||
- 'Gemfile*'
|
||||
|
||||
Reference in New Issue
Block a user