Forked code should not automatically receive secrets

If somebody can open a pull request that runs your pipeline with your secrets, they can take your secrets.

It is a well-known pattern and still a common misconfiguration, because the convenient default is for everything to run the same way. Builds from untrusted sources need to run without credentials, or not automatically at all.

More on CI/CD security