Running GitHub Actions on the code in a Pull Request from a fork

Viewed 4054

I have an origin repo in GitHub and I have created a local fork that I am developing on. I have a GitHub Action that runs a Bandit security check, but when I push changes and create a Pull request from a branch in my fork, the Bandit test runs on the code that is currently in the origin repo, not on the new code in the PR.

How can I run the GitHub Action Workflow on the code that is inside the Pull Request?

FYI: here is the "on" statement currently in the yml file:

name: Security scan
on:
  push:
    branches:
      - master
  pull_request_target:
    branches: [main, dev]
4 Answers

[...] we’ve added a new pull_request_target event, which behaves in an almost identical way to the pull_request event with the same set of filters and payload. However, instead of running against the workflow and code from the merge commit, the event runs against the workflow and code from the base of the pull request.

Source: https://github.blog/2020-08-03-github-actions-improvements-for-fork-and-pull-request-workflows/

You can still checkout the code from the pull request with the following step:

- uses: actions/checkout@v2
  with:
    ref: ${{github.event.pull_request.head.ref}}
    repository: ${{github.event.pull_request.head.repo.full_name}}

Source: https://github.community/t/running-code-from-forks-with-pull-request-target/126688/6

Triggers the workflow on push or pull request events

Using pull_request

name: CI
on: [push, pull_request]
jobs:
  python-tests:
    runs-on: ubuntu-latest

    steps:
      ...

I used this blog post to setup github actions for one of my repositories. Check that out, it might help. Also reading the documentation from github might help.

Regarding your specific problem as also mentioned by the others you should use pull_request. Here is an example (This CI jobs is only triggerd for pull requests onto the main branch):

name: Tests                                                                                 
on:
  pull_request:
    branches:
    - main                                                                                  
jobs:                                                                                       
  tests:                                                                                    
    runs-on: ubuntu-latest                                                                  
    steps:                                                                                  
    - uses: actions/checkout@v2                                                             
    - uses: actions/setup-python@v1                                                         
      with:                                                                                 
        python-version: 3.8                                                                 
        architecture: x64                                                                   
    - run: # security scan bandit
Related