We should decide between `pull_request` and `pull_request_target` workflow type, and between using automatic short-lived `GITHUB_TOKEN` and PAT.