Skip to content

Misleading wording regarding permissions and access to secrets in pull_request workflows #25117

@monholm

Description

@monholm

Code of Conduct

What article on docs.github.com is affected?

https://docs.github.com/en/actions/security-guides/security-hardening-for-github-actions#accessing-secrets

What part(s) of the article would you like to see updated?

The phrase Workflows triggered using the pull_request event have read-only permissions and have no access to secrets is incorrect, as this is only the case for workflows triggered from a fork.

The phrase should be updated to clarify that this is not the case for pull requests from a branch within the repository.

Additional information

No response

Metadata

Metadata

Assignees

No one assigned

    Labels

    contentThis issue or pull request belongs to the Docs Content team

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions