Throwaway repository for isolated security research — reproduces a
pull_request_target gatekeeper + GitHub Environment approval pattern to test,
in a repo I own, whether an environment's required-reviewer approval is enforced
per workflow run on a synchronize event.
No third-party or production system is involved. The workflow only runs a benign
marker; nothing is exfiltrated. See .github/workflows/repro-prtarget.yml.