Fix CI checkout after github new security policy

Github now fails with the following error when using
`on: pull_request_target`:
```
Error: Refusing to check out fork pull request code from a
'pull_request_target' workflow. This workflow runs with the base
repository's GITHUB_TOKEN, secrets, default-branch cache scope, and
runner access. Fetching and executing a fork's code in that trusted
context commonly leads to "pwn request" vulnerabilities. To opt in,
review the risks at https://gh.io/securely-using-pull_request_target and
set 'allow-unsafe-pr-checkout: true' on the actions/checkout step.
```

This reverts https://github.com/nvim-lua/kickstart.nvim/pull/571
and reopens https://github.com/nvim-lua/kickstart.nvim/pull/570
This commit is contained in:
orip
2026-08-07 18:39:45 +03:00
parent bd53f28e49
commit b84f0b775d
+5 -3
View File
@@ -1,6 +1,10 @@
# Check Lua Formatting
name: Check Lua Formatting
on: pull_request_target
on:
push:
branches:
- master
pull_request:
jobs:
stylua-check:
@@ -10,8 +14,6 @@ jobs:
steps:
- name: Checkout Code
uses: actions/checkout@v6
with:
ref: ${{ github.event.pull_request.head.sha }}
- name: Stylua Check
uses: JohnnyMorganz/stylua-action@v4
with: