prevent attacker sneaking in a pointer outside the origin default branch or owned by a fork
prevent attacker sneaking in a pointer outside the origin default branch or owned by a fork