GitHub lets you suffix any PR with .diff or .patch to get the raw diff/patch.
e.g.
https://github.com/github/gitignore/pull/4908.diff
https://github.com/github/gitignore/pull/4908.patch
For a public repo it redirects straight to the raw content on patch-diff.githubusercontent.com with no token needed:
https://patch-diff.githubusercontent.com/raw/github/gitignore/pull/4908.diff
For a private repo, that redirect instead carries a short-lived access token in the query string, e.g.:
https://patch-diff.githubusercontent.com/raw/<owner>/<private-repo>/pull/<N>.diff?token=AALPL5XXXXXXXXXXXXXXXXX
Either way, you fetch it with curl and pipe straight into git apply:
curl -sL "https://github.com/github/gitignore/pull/4908.diff" | git applyWe can use this to squash a PR into a single commit — effectively cherry-picking a PR (but not technically, since it's a diff apply, not a real cherry-pick).
Note: for public repos like this one, no token is generated at all — the token only shows up when the redirect target requires your authenticated session to read a private repo's diff.
If you have the GitHub CLI installed and authenticated, you can skip the curl/token dance entirely — gh handles auth for both public and private repos:
gh pr diff 4908 --repo github/gitignore | git applyOr to get a patch with commit metadata (so you can git am it instead, preserving author/message):
gh pr diff 4908 --repo github/gitignore --patch | git am