See https://securitylab.github.com/research/github-actions-preventing-pwn-requests/ for notes on how to do this safely