Maybe it's possible thanks to [this](https://github.blog/changelog/2026-06-18-control-who-and-what-triggers-github-actions-workflows/) github feature. See [#t-infra > GitHub workflow policy](https://rust-lang.zulipchat.com/#narrow/channel/242791-t-infra/topic/GitHub.20workflow.20policy/with/604856630) If it's not possible with this feature (eg we want an explicit allow list probably), we can use https://github.com/rust-lang/crabwatch
Maybe it's possible thanks to this github feature.
See #t-infra > GitHub workflow policy
If it's not possible with this feature (eg we want an explicit allow list probably), we can use https://github.com/rust-lang/crabwatch