From b84f0b775d991de3640b752eee8cb857d4bbfe27 Mon Sep 17 00:00:00 2001 From: orip Date: Fri, 7 Aug 2026 18:39:45 +0300 Subject: [PATCH] Fix CI checkout after github new security policy Github now fails with the following error when using `on: pull_request_target`: ``` Error: Refusing to check out fork pull request code from a 'pull_request_target' workflow. This workflow runs with the base repository's GITHUB_TOKEN, secrets, default-branch cache scope, and runner access. Fetching and executing a fork's code in that trusted context commonly leads to "pwn request" vulnerabilities. To opt in, review the risks at https://gh.io/securely-using-pull_request_target and set 'allow-unsafe-pr-checkout: true' on the actions/checkout step. ``` This reverts https://github.com/nvim-lua/kickstart.nvim/pull/571 and reopens https://github.com/nvim-lua/kickstart.nvim/pull/570 --- .github/workflows/stylua.yml | 8 +++++--- 1 file changed, 5 insertions(+), 3 deletions(-) diff --git a/.github/workflows/stylua.yml b/.github/workflows/stylua.yml index eb60303..2039108 100644 --- a/.github/workflows/stylua.yml +++ b/.github/workflows/stylua.yml @@ -1,6 +1,10 @@ # Check Lua Formatting name: Check Lua Formatting -on: pull_request_target +on: + push: + branches: + - master + pull_request: jobs: stylua-check: @@ -10,8 +14,6 @@ jobs: steps: - name: Checkout Code uses: actions/checkout@v6 - with: - ref: ${{ github.event.pull_request.head.sha }} - name: Stylua Check uses: JohnnyMorganz/stylua-action@v4 with: