certslothcertsloth
GH-200/Topic 01

GitHub / Associate

Events, Inputs and Workflow Trust

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: The trigger chooses both the event and the trust boundary.

Must remember

Workflow files live under .github/workflows/ and declare events with on. Push and pull-request events support branch/path filters; when both apply, reason about their combined conditions. Manual workflow_dispatch inputs can be typed and required. workflow_call exposes a reusable workflow interface with declared inputs/secrets. repository_dispatch receives an external event through the API.

Scheduled workflows use supported cron scheduling and default-branch behavior; they are not precise real-time schedulers and may be delayed. Know which events require the workflow file on the default branch. Inspect event action types and payload fields rather than assuming every event contains a pull-request number.

Untrusted contribution workflows need restricted permissions and secrets. pull_request_target runs in the base-repository context and requires special care; never combine privileged credentials with execution of untrusted proposed code. Current checkout safeguards help, but they do not make every downloaded script or artifact trusted.

Validate manual/external inputs against the operation's expected values. A declared string input can still contain malicious shell characters. Pass data through safe environment/argument handling and validate it; do not interpolate untrusted expressions directly into executable script text.

Set permissions at the smallest suitable scope and choose events that fit the required operation. Prevent unintended recursive automation while understanding exceptions for explicit dispatches. A successful token-authenticated API call does not necessarily trigger every downstream workflow as a human push would.

Choose under exam pressure

Requirement Choice and reason
Human starts a parameterized workflow workflow_dispatch with validated inputs.
A workflow calls shared orchestration workflow_call.
Test a fork contribution Restricted untrusted-code workflow without privileged secrets.

Traps

  • An event name alone does not prove its payload has every expected field.
  • A privileged base-context workflow must not execute untrusted PR code.

Active recall

1. workflow_dispatch versus workflow_call?

Manual invocation versus a reusable workflow called by another workflow.

2. Why inspect default-branch requirements?

Some event types only trigger workflows available there.

3. Why is a string input not inherently safe?

Its content can become executable code if interpolated into a script.

4. Why can a schedule run late?

Hosted scheduling is not an exact-time execution guarantee.

5. What determines a safe trigger?

The required event behavior plus the trust and permissions of the code/data it exposes.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.