Add org-wide reusable PR labeler (INFRA-56) (#50)

Add callable-labeler.yaml, a reusable workflow that carries the label
rules inline as the single source of truth and writes them to the runner
at execution time, so caller repos need only a short caller workflow and
no per-repo labeler.yml. Triggered by callers on pull_request (private org
takes no fork PRs); requires contents:read + pull-requests:write +
issues:write on every caller so labeler@v5 can create missing labels.

Remove the workflow-templates/labeler.yml starter it supersedes (no
ruleset workflows-rule or compliance-audit reference depends on it).

Add the repo's own dependabot.yml (github-actions, weekly, grouped
minor+patch) to keep the action pins current per the Pinning Principle.
This commit is contained in:
Adam Moussa 2026-06-11 13:34:39 -04:00 • committed by GitHub
parent 023206e695
commit 31bb01d1e9
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
4 changed files with 99 additions and 27 deletions

11
.github/dependabot.yml vendored Normal file
View file

@ -0,0 +1,11 @@
version: 2
updates:
- package-ecosystem: "github-actions"
directory: "/"
schedule:
interval: "weekly"
groups:
minor-and-patch:
update-types:
- "minor"
- "patch"

88
.github/workflows/callable-labeler.yaml vendored Normal file
View file

@ -0,0 +1,88 @@
name: Labeler
# Reusable PR auto-labeler for all Sea-Haven-Industries repos.
#
# The label rules live HERE as the single source of truth and are written to the
# runner at execution time, so caller repos need only a short caller workflow and
# no per-repo labeler.yml.
#
# Callers trigger this on `pull_request` (NOT pull_request_target): every org repo
# is private and takes no fork PRs, so the lower-privilege event is sufficient and
# avoids the pull_request_target pwn-request surface. Because `pull_request` runs
# the workflow from the PR merge commit, the Labeler check appears on the PR that
# first adds the caller — an absent or failed Labeler check means a missing
# permission grant on the caller, not "expected" behaviour.
#
# Callers MUST grant all three permissions below. Reusable-workflow permissions can
# only be downgraded from the caller, so a caller that omits one (e.g. issues:write)
# either fails to create labels or triggers a silent startup_failure:
# permissions:
# contents: read
# pull-requests: write
# issues: write
on:
workflow_call:
permissions:
contents: read
pull-requests: write
issues: write
jobs:
label:
runs-on: ubuntu-latest
steps:
- name: Write central label rules
run: |
mkdir -p "${{ runner.temp }}"
cat > "${{ runner.temp }}/labeler.yml" <<'EOF'
infra:
- changed-files:
- any-glob-to-any-file:
- 'lib/**'
- 'bin/**'
- 'cdk/**'
- 'cdk.json'
- 'template.yaml'
- 'template.yml'
- '**/template.yaml'
- 'samconfig.toml'
app:
- changed-files:
- any-glob-to-any-file:
- 'src/**'
- 'functions/**'
- 'lambdas/**'
- 'api/**'
- 'services/**'
ci:
- changed-files:
- any-glob-to-any-file:
- '.github/workflows/**'
docs:
- changed-files:
- any-glob-to-any-file:
- '**/*.md'
dependencies:
- changed-files:
- any-glob-to-any-file:
- '**/requirements.txt'
- '**/package.json'
- '**/package-lock.json'
- '**/*.csproj'
- '**/packages.lock.json'
- '.github/dependabot.yml'
tests:
- changed-files:
- any-glob-to-any-file:
- '**/tests/**'
- '**/test/**'
- '**/*.test.ts'
- '**/*_test.py'
EOF
- uses: actions/labeler@v5
with:
repo-token: ${{ secrets.GITHUB_TOKEN }}
configuration-path: ${{ runner.temp }}/labeler.yml
sync-labels: false

View file

@ -1,7 +0,0 @@
{
"name": "Sea Haven — PR Labeler",
"description": "Auto-labels PRs by changed paths (infra / lambda / ci / docs). Requires a .github/labeler.yml config.",
"iconName": "octicon-tag",
"categories": ["Automation", "Pull requests"],
"filePatterns": [".github/labeler\\.ya?ml$"]
}

View file

@ -1,20 +0,0 @@
name: Labeler
on: [pull_request_target]
permissions:
contents: read
pull-requests: write
jobs:
label:
runs-on: ubuntu-latest
steps:
# Requires .github/labeler.yml in this repo, e.g.:
# infra: [ 'cdk/**', 'template.yaml', 'oidc-deploy-roles.yaml' ]
# lambda: [ 'lambdas/**', 'src/**', 'functions/**' ]
# ci: [ '.github/workflows/**' ]
# docs: [ '**/*.md' ]
- uses: actions/labeler@v5
with:
repo-token: ${{ secrets.GITHUB_TOKEN }}
sync-labels: true