diff --git a/.github/workflows/new_contributor_pr.yml b/.github/workflows/new_contributor_pr.yml index 168cae1b2..cad5bc59e 100644 --- a/.github/workflows/new_contributor_pr.yml +++ b/.github/workflows/new_contributor_pr.yml @@ -1,6 +1,10 @@ name: New contributor message on: + # Safety + # This workflow uses pull_request_target so it can run with write permissions on first-time contributor PRs. + # It is safe because it does not check out or execute any code from the pull request and + # only uses the pinned, trusted actions/first-interaction action pull_request_target: types: [opened] branches: