# Common Events — GitHub Actions

Source: https://www.skillbyai.com/en/github-actions/t-events

> push, pull_request, workflow_dispatch and more.

## Pick the right trigger

`push` runs on commits to branches or tags; `pull_request` runs for pull requests in the context of the merge result, with a read-only token for forks; `workflow_dispatch` adds a manual "Run workflow" button with optional inputs; `schedule` runs on cron; `release`, `issues` and many others react to repository activity. `pull_request_target` runs with the base repository's permissions and secrets and is dangerous when it checks out pull request code; avoid it unless you fully understand the risk.

## Run when it matters

Events, branch and path filters, and schedules decide when workflows start.

![Three ideas: events, filters, schedules.](assets/figures/github-actions/section-2-map.svg) — Figure 2.1 — Events, filters and schedules.

## A trigger block

Not linted or run here; check the GitHub Actions documentation for current syntax.

```yaml
on:
  push:
    branches: [main]
    tags: ["v*"]
  pull_request:
    branches: [main]
  workflow_dispatch:
    inputs:
      environment:
        type: choice
        options: [staging, production]
  schedule:
    - cron: "30 2 * * 1"     # 02:30 UTC every Monday
```

## Avoid pull_request_target with checkout

Checking out and running pull request code under pull_request_target gives untrusted code your secrets; use pull_request instead.

**Quiz:** Which trigger adds a manual "Run workflow" button?

- [ ] push
- [x] workflow_dispatch
- [ ] schedule
- [ ] pull_request

*Answer:* workflow_dispatch. Manual runs with inputs.
