As these APIs only work on forks, and it's not possible to change the visibility of a fork from its parent, only testing the API access pattern against the head is sufficient. Also it is not a breaking change due to checkTokenPublicOnly middleware already enforcing this for public-only scopes, and the lack of ability to change a fork's visibility.