Why forks need a second workflow
A pull_request run from a fork gets a read-only token and no OIDC token, so the step prints a notice and skips the push. A workflow_run workflow runs in your repository once the build finishes, with your permissions. It downloads the numbers the fork's build measured and pushes them for the pull request.
It never checks out or runs the fork's code, and buildstats only lets these runs write to a pull request, never to your default branch.
Save the metrics as a file
In the build workflow, write the metrics to a JSON file in the metric format and upload it. Keep your regular buildstats step for pushes and pull requests from your own branches.
- run: echo '{"bundle_size": 1832}' > buildstats.json- uses: actions/upload-artifact@v7 with: name: buildstats path: buildstats.jsonPush from workflow_run
Add a second workflow. workflows must match the name of the build workflow, and the last condition leaves pull requests from your own branches to the regular step.
name: buildstats on: workflow_run: workflows: [Build] types: [completed] permissions: actions: read contents: read id-token: write pull-requests: write jobs: push: if: >- github.event.workflow_run.event == 'pull_request' && github.event.workflow_run.conclusion == 'success' && github.event.workflow_run.head_repository.full_name != github.repository runs-on: ubuntu-latest steps: - uses: actions/download-artifact@v8 with: name: buildstats run-id: ${{ github.event.workflow_run.id }} github-token: ${{ github.token }} - uses: buildstats-io/action@v1 with: file: buildstats.json sha: ${{ github.event.workflow_run.head_sha }}The step finds the pull request for head_sha, records the metrics on it and updates its comment.
Good to know
- GitHub only runs
workflow_runworkflows that are on the default branch, so merge this one before you try it on a fork. - The fork controls the numbers in the artifact, and they can only land on its own pull request.
pull_request_targetruns record on the pull request too, with the number and head commit from the event. They run with your permissions, so never build the fork's code in them.