Three items #47 absorbed from #46, held back so a dead badge would not sit beside an unresolved r-universe one. Both resolve now that v0.4.0 is tagged. - R-CMD-check badge pointing at the GitHub mirror's workflow, where the 4-platform matrix actually runs. - A pull_request_target workflow explaining the mirror flow on every incoming PR. A PR here is landed on Gitea and syncs back, and because the merge preserves the contributor's commits at their original SHAs, GitHub marks the PR 'Merged' with nobody visibly clicking Merge. To a first-time contributor that reads as rejection. Say so before it happens. pull_request_target rather than pull_request because a fork PR's token is read-only under the latter -- it could not comment, which is the entire job. That is only safe because this never checks out or runs contributor code; the file says so and says not to add a checkout. - CONTRIBUTING's release checklist now spells out that the tag goes on Gitea and the mirror carries it, and that r-universe does NOT pick up a release until packages.json's branch pin is edited. '*release' would automate it but needs a GitHub Release object, and the mirror pushes tags only -- so it would silently never update. Learned while doing this release.