mirror of
https://github.com/Sea-Haven-Industries/.github.git
synced 2026-10-05 03:42:04 +00:00
Run the org PR labeler on .github's own PRs
Add a thin caller so the .github repo invokes its own reusable callable-labeler.yaml on pull_request, like every consumer repo does. Without a caller the workflow_call-only labeler never runs on .github's own PRs (this is why #61 wasn't auto-labeled). Grants the three permissions the reusable requires (contents:read, pull-requests:write, issues:write).
This commit is contained in:
parent
5937ab73e6
commit
9353a212c3
1 changed files with 25 additions and 0 deletions
25
.github/workflows/labeler.yaml
vendored
Normal file
25
.github/workflows/labeler.yaml
vendored
Normal file
|
|
@ -0,0 +1,25 @@
|
||||||
|
name: labeler
|
||||||
|
|
||||||
|
# Thin caller that runs the org-wide reusable PR labeler (callable-labeler.yaml)
|
||||||
|
# on THIS repo's own pull requests. The .github repo is the single source of truth
|
||||||
|
# for the reusable workflows, but — like any consumer repo — it must invoke them
|
||||||
|
# via a caller to use them on itself; without this, the labeler never runs on
|
||||||
|
# .github's own PRs (the reusable is `workflow_call`-only).
|
||||||
|
#
|
||||||
|
# Permissions are load-bearing: callers MUST grant all three below. Reusable-
|
||||||
|
# workflow permissions can only be downgraded from the caller, so omitting one
|
||||||
|
# (e.g. issues:write) either fails to create labels or triggers a silent
|
||||||
|
# startup_failure. `pull_request` (NOT pull_request_target) is correct here — the
|
||||||
|
# org takes no fork PRs, so the lower-privilege event is sufficient.
|
||||||
|
|
||||||
|
on:
|
||||||
|
pull_request:
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
pull-requests: write
|
||||||
|
issues: write
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
label:
|
||||||
|
uses: ./.github/workflows/callable-labeler.yaml
|
||||||
Loading…
Add table
Reference in a new issue