DevOpsInterviewPrep logo
CI/CD, Release Engineering & GitOps / 20
hard★ EssentialNewCloudflareGitLabStripe

A stranger opens a pull request from their fork. What can that PR execute in your pipeline, and where does pull_request_target go wrong?

Public fork PRs normally get a read-only token and no repository secrets. Privileged triggers, runner access and untrusted shell input can break that boundary.

Updated Sep 2026 · Grounded in researched DevOps, SRE and platform engineering interview loops, written to a senior-engineer editorial bar, and never padded to hit a word count.

Public fork PRs normally get a read-only token and no repository secrets. Privileged triggers, runner access and untrusted shell input can break that boundary.

an account raises the per-topic limit · no card
UP NEXT ON YOUR JOURNEY
DISCUSSION · 0

Nothing here yet. Say how you would answer it.