Rendered from docs/process/decisions/0014-the-boundary-against-a-fork-is-the-approval-of-outside-runs-and-a-person-reads-a-github-diff-before-approving-one.md in the Headwater corpus. Every document on this half of the site is typed by the taxonomy the descriptor names: corpus.json.

The boundary against a fork is the approval of outside runs, and a person reads a .github diff before approving one

Context

Before this record, the reasons lived in comments of .github/workflows/ci.yml on 2026-09-27. The comments were header rule 2 (lines 39 to 42). Two triggers, one verdict holds the argument and the measurements.

A fork runs its own copy of ci.yml (HW-PD-0013). So the boundary against a hostile fork cannot be an expression in that file.

Decision

The setting is the boundary. The repository setting fork_pr_contributor_approval: all_external_contributors holds every run from an outside contributor until a maintainer approves it. That setting keeps outside code off the runners, and no expression in ci.yml does.

Read the diff first. A maintainer does not approve a run whose diff touches .github/ before they read that diff. No expression in ci.yml does this work for them.

Consequences

The protection of the runners depends on one repository setting and on one review by a person. A change to the setting changes the boundary, and no file in this repository shows that change.

A condition added to ci.yml to stop a fork is not a second boundary. The fork deletes it in its own copy.

This record reopens if the approval setting changes, or if a second maintainer approves outside runs.