mirror of
https://github.com/Sea-Haven-Industries/.github.git
synced 2026-10-03 20:13:16 +00:00
Add org-wide reusable PR labeler (INFRA-56) (#50)
Add callable-labeler.yaml, a reusable workflow that carries the label rules inline as the single source of truth and writes them to the runner at execution time, so caller repos need only a short caller workflow and no per-repo labeler.yml. Triggered by callers on pull_request (private org takes no fork PRs); requires contents:read + pull-requests:write + issues:write on every caller so labeler@v5 can create missing labels. Remove the workflow-templates/labeler.yml starter it supersedes (no ruleset workflows-rule or compliance-audit reference depends on it). Add the repo's own dependabot.yml (github-actions, weekly, grouped minor+patch) to keep the action pins current per the Pinning Principle.
This commit is contained in:
parent
023206e695
commit
31bb01d1e9
4 changed files with 99 additions and 27 deletions
11
.github/dependabot.yml
vendored
Normal file
11
.github/dependabot.yml
vendored
Normal file
|
|
@ -0,0 +1,11 @@
|
||||||
|
version: 2
|
||||||
|
updates:
|
||||||
|
- package-ecosystem: "github-actions"
|
||||||
|
directory: "/"
|
||||||
|
schedule:
|
||||||
|
interval: "weekly"
|
||||||
|
groups:
|
||||||
|
minor-and-patch:
|
||||||
|
update-types:
|
||||||
|
- "minor"
|
||||||
|
- "patch"
|
||||||
88
.github/workflows/callable-labeler.yaml
vendored
Normal file
88
.github/workflows/callable-labeler.yaml
vendored
Normal file
|
|
@ -0,0 +1,88 @@
|
||||||
|
name: Labeler
|
||||||
|
|
||||||
|
# Reusable PR auto-labeler for all Sea-Haven-Industries repos.
|
||||||
|
#
|
||||||
|
# The label rules live HERE as the single source of truth and are written to the
|
||||||
|
# runner at execution time, so caller repos need only a short caller workflow and
|
||||||
|
# no per-repo labeler.yml.
|
||||||
|
#
|
||||||
|
# Callers trigger this on `pull_request` (NOT pull_request_target): every org repo
|
||||||
|
# is private and takes no fork PRs, so the lower-privilege event is sufficient and
|
||||||
|
# avoids the pull_request_target pwn-request surface. Because `pull_request` runs
|
||||||
|
# the workflow from the PR merge commit, the Labeler check appears on the PR that
|
||||||
|
# first adds the caller — an absent or failed Labeler check means a missing
|
||||||
|
# permission grant on the caller, not "expected" behaviour.
|
||||||
|
#
|
||||||
|
# Callers MUST grant all three permissions below. Reusable-workflow permissions can
|
||||||
|
# only be downgraded from the caller, so a caller that omits one (e.g. issues:write)
|
||||||
|
# either fails to create labels or triggers a silent startup_failure:
|
||||||
|
# permissions:
|
||||||
|
# contents: read
|
||||||
|
# pull-requests: write
|
||||||
|
# issues: write
|
||||||
|
|
||||||
|
on:
|
||||||
|
workflow_call:
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
pull-requests: write
|
||||||
|
issues: write
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
label:
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- name: Write central label rules
|
||||||
|
run: |
|
||||||
|
mkdir -p "${{ runner.temp }}"
|
||||||
|
cat > "${{ runner.temp }}/labeler.yml" <<'EOF'
|
||||||
|
infra:
|
||||||
|
- changed-files:
|
||||||
|
- any-glob-to-any-file:
|
||||||
|
- 'lib/**'
|
||||||
|
- 'bin/**'
|
||||||
|
- 'cdk/**'
|
||||||
|
- 'cdk.json'
|
||||||
|
- 'template.yaml'
|
||||||
|
- 'template.yml'
|
||||||
|
- '**/template.yaml'
|
||||||
|
- 'samconfig.toml'
|
||||||
|
app:
|
||||||
|
- changed-files:
|
||||||
|
- any-glob-to-any-file:
|
||||||
|
- 'src/**'
|
||||||
|
- 'functions/**'
|
||||||
|
- 'lambdas/**'
|
||||||
|
- 'api/**'
|
||||||
|
- 'services/**'
|
||||||
|
ci:
|
||||||
|
- changed-files:
|
||||||
|
- any-glob-to-any-file:
|
||||||
|
- '.github/workflows/**'
|
||||||
|
docs:
|
||||||
|
- changed-files:
|
||||||
|
- any-glob-to-any-file:
|
||||||
|
- '**/*.md'
|
||||||
|
dependencies:
|
||||||
|
- changed-files:
|
||||||
|
- any-glob-to-any-file:
|
||||||
|
- '**/requirements.txt'
|
||||||
|
- '**/package.json'
|
||||||
|
- '**/package-lock.json'
|
||||||
|
- '**/*.csproj'
|
||||||
|
- '**/packages.lock.json'
|
||||||
|
- '.github/dependabot.yml'
|
||||||
|
tests:
|
||||||
|
- changed-files:
|
||||||
|
- any-glob-to-any-file:
|
||||||
|
- '**/tests/**'
|
||||||
|
- '**/test/**'
|
||||||
|
- '**/*.test.ts'
|
||||||
|
- '**/*_test.py'
|
||||||
|
EOF
|
||||||
|
- uses: actions/labeler@v5
|
||||||
|
with:
|
||||||
|
repo-token: ${{ secrets.GITHUB_TOKEN }}
|
||||||
|
configuration-path: ${{ runner.temp }}/labeler.yml
|
||||||
|
sync-labels: false
|
||||||
|
|
@ -1,7 +0,0 @@
|
||||||
{
|
|
||||||
"name": "Sea Haven — PR Labeler",
|
|
||||||
"description": "Auto-labels PRs by changed paths (infra / lambda / ci / docs). Requires a .github/labeler.yml config.",
|
|
||||||
"iconName": "octicon-tag",
|
|
||||||
"categories": ["Automation", "Pull requests"],
|
|
||||||
"filePatterns": [".github/labeler\\.ya?ml$"]
|
|
||||||
}
|
|
||||||
|
|
@ -1,20 +0,0 @@
|
||||||
name: Labeler
|
|
||||||
on: [pull_request_target]
|
|
||||||
|
|
||||||
permissions:
|
|
||||||
contents: read
|
|
||||||
pull-requests: write
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
label:
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
steps:
|
|
||||||
# Requires .github/labeler.yml in this repo, e.g.:
|
|
||||||
# infra: [ 'cdk/**', 'template.yaml', 'oidc-deploy-roles.yaml' ]
|
|
||||||
# lambda: [ 'lambdas/**', 'src/**', 'functions/**' ]
|
|
||||||
# ci: [ '.github/workflows/**' ]
|
|
||||||
# docs: [ '**/*.md' ]
|
|
||||||
- uses: actions/labeler@v5
|
|
||||||
with:
|
|
||||||
repo-token: ${{ secrets.GITHUB_TOKEN }}
|
|
||||||
sync-labels: true
|
|
||||||
Loading…
Add table
Reference in a new issue