Until you unintentionally pull in a vulnerability or intentional backdoor. Every PR needs to be reviewed.
Why would you review a PR that you are never going to merge?
I don't think every PR needs reviewing. Some PRs we can ignore just by taking a quick look at what the PR claims to do. This only requires a quick glance, not a PR review.