Back to buildstats

DOCS

Fork pull requests

Fork pull requests get no OIDC token. Upload the metrics as an artifact and push them from a workflow_run workflow, which records them on the pull request, never on main.

Updated October 7, 2026

01

Why forks need a second workflow

A pull_request run from a fork gets a read-only token and no OIDC token, so the step prints a notice and skips the push. A workflow_run workflow runs in your repository once the build finishes, with your permissions. It downloads the numbers the fork's build measured and pushes them for the pull request.

It never checks out or runs the fork's code, and buildstats only lets these runs write to a pull request, never to your default branch.

02

Save the metrics as a file

In the build workflow, write the metrics to a JSON file in the metric format and upload it. Keep your regular buildstats step for pushes and pull requests from your own branches.

.github/workflows/build.yml
- run: echo '{"bundle_size": 1832}' > buildstats.json- uses: actions/upload-artifact@v7  with:    name: buildstats    path: buildstats.json
03

Push from workflow_run

Add a second workflow. workflows must match the name of the build workflow, and the last condition leaves pull requests from your own branches to the regular step.

.github/workflows/buildstats.yml
name: buildstats on:  workflow_run:    workflows: [Build]    types: [completed] permissions:  actions: read  contents: read  id-token: write  pull-requests: write jobs:  push:    if: >-      github.event.workflow_run.event == 'pull_request' &&      github.event.workflow_run.conclusion == 'success' &&      github.event.workflow_run.head_repository.full_name != github.repository    runs-on: ubuntu-latest    steps:      - uses: actions/download-artifact@v8        with:          name: buildstats          run-id: ${{ github.event.workflow_run.id }}          github-token: ${{ github.token }}      - uses: buildstats-io/action@v1        with:          file: buildstats.json          sha: ${{ github.event.workflow_run.head_sha }}

The step finds the pull request for head_sha, records the metrics on it and updates its comment.

04

Good to know

  • GitHub only runs workflow_run workflows that are on the default branch, so merge this one before you try it on a fork.
  • The fork controls the numbers in the artifact, and they can only land on its own pull request.
  • pull_request_target runs record on the pull request too, with the number and head commit from the event. They run with your permissions, so never build the fork's code in them.
Still have a question?Talk to us