From 9353a212c307a132272310a792c8c6ca1b5abd63 Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Tue, 16 Jun 2026 15:50:09 -0400 Subject: [PATCH] Run the org PR labeler on .github's own PRs Add a thin caller so the .github repo invokes its own reusable callable-labeler.yaml on pull_request, like every consumer repo does. Without a caller the workflow_call-only labeler never runs on .github's own PRs (this is why #61 wasn't auto-labeled). Grants the three permissions the reusable requires (contents:read, pull-requests:write, issues:write). --- .github/workflows/labeler.yaml | 25 +++++++++++++++++++++++++ 1 file changed, 25 insertions(+) create mode 100644 .github/workflows/labeler.yaml diff --git a/.github/workflows/labeler.yaml b/.github/workflows/labeler.yaml new file mode 100644 index 0000000..6f3a8c0 --- /dev/null +++ b/.github/workflows/labeler.yaml @@ -0,0 +1,25 @@ +name: labeler + +# Thin caller that runs the org-wide reusable PR labeler (callable-labeler.yaml) +# on THIS repo's own pull requests. The .github repo is the single source of truth +# for the reusable workflows, but — like any consumer repo — it must invoke them +# via a caller to use them on itself; without this, the labeler never runs on +# .github's own PRs (the reusable is `workflow_call`-only). +# +# Permissions are load-bearing: callers MUST grant all three below. Reusable- +# workflow permissions can only be downgraded from the caller, so omitting one +# (e.g. issues:write) either fails to create labels or triggers a silent +# startup_failure. `pull_request` (NOT pull_request_target) is correct here — the +# org takes no fork PRs, so the lower-privilege event is sufficient. + +on: + pull_request: + +permissions: + contents: read + pull-requests: write + issues: write + +jobs: + label: + uses: ./.github/workflows/callable-labeler.yaml