name: labeler # Thin caller that runs the org-wide reusable PR labeler (callable-labeler.yaml) # on THIS repo's own pull requests. The .github repo is the single source of truth # for the reusable workflows, but — like any consumer repo — it must invoke them # via a caller to use them on itself; without this, the labeler never runs on # .github's own PRs (the reusable is `workflow_call`-only). # # Permissions are load-bearing: callers MUST grant all three below. Reusable- # workflow permissions can only be downgraded from the caller, so omitting one # (e.g. issues:write) either fails to create labels or triggers a silent # startup_failure. `pull_request` (NOT pull_request_target) is correct here — the # org takes no fork PRs, so the lower-privilege event is sufficient. on: pull_request: permissions: contents: read pull-requests: write issues: write jobs: label: uses: ./.github/workflows/callable-labeler.yaml