.github/workflows: switch to pull_request_target trigger
Switch the trigger from `pull_request` to `pull_request_target` so that the workflow definition on `main` is evaluated for PRs targeting active release branches (main, umbrella, tentacle, squid). This allows the check to run cleanly across release branches without requiring workflow file backports to each branch. Additionally: - Update `src/script/verify-qa` to accept an optional target directory argument ($1). - Run the trusted `verify-qa` script from `main` against the checked-out PR directory (`./pull_request`). The concern of exfiltrating secrets is important but not relevant here: we're not using the secrets in the definition and we explicitly downgrade the github token to `read` permission. Signed-off-by: Patrick Donnelly <pdonnell@ibm.com>
P
Patrick Donnelly committed
9336dcba488298e6fa3ed32f0fbde6be2c3d17cf
Parent: e82ccd0