SkillByAIOpen interactive version →

Lesson 4 / 25

Common Events

push, pull_request, workflow_dispatch and more.

Pick the right trigger

push runs on commits to branches or tags; pull_request runs for pull requests in the context of the merge result, with a read-only token for forks; workflow_dispatch adds a manual "Run workflow" button with optional inputs; schedule runs on cron; release, issues and many others react to repository activity. pull_request_target runs with the base repository's permissions and secrets and is dangerous when it checks out pull request code; avoid it unless you fully understand the risk.

Run when it matters

Events, branch and path filters, and schedules decide when workflows start.

Figure 2.1 — Events, filters and schedules.

A trigger block

Not linted or run here; check the GitHub Actions documentation for current syntax.

on:
  push:
    branches: [main]
    tags: ["v*"]
  pull_request:
    branches: [main]
  workflow_dispatch:
    inputs:
      environment:
        type: choice
        options: [staging, production]
  schedule:
    - cron: "30 2 * * 1"     # 02:30 UTC every Monday

Avoid pull_request_target with checkout

Checking out and running pull request code under pull_request_target gives untrusted code your secrets; use pull_request instead.

Quick check: Which trigger adds a manual "Run workflow" button?

  • push
  • workflow_dispatch
  • schedule
  • pull_request
Answer

workflow_dispatch — Manual runs with inputs.