`pull_request_target` is always running on main branch

Hello there!

I am using a GitHub action to build my code. And the code uses a private go module. So I use Action secrets to fetch the private module.

After the recent breaking change of dependabot, I am using pull_request_target event instead of pull_request. But today I have discovered that, all my actions were running on the code of my main branch, not on the code of the branch that dependabot created.

What to do?

I’m having the same issue. Were you able to resolve it?