.github/.github/workflows/callable-labeler.yaml
dependabot[bot] 555d07c3a2
Some checks are pending
ci / ci / ci (push) Waiting to run
Bump actions/labeler from 6.2.0 to 7.0.0 (#91)
Bumps [actions/labeler](https://github.com/actions/labeler) from 6.2.0 to 7.0.0.
- [Release notes](https://github.com/actions/labeler/releases)
- [Commits](b8dd2d9be0...bf12e9b00b)

---
updated-dependencies:
- dependency-name: actions/labeler
  dependency-version: 7.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-27 14:08:27 -04:00

137 lines
4.7 KiB
YAML

name: Labeler
# Reusable PR auto-labeler for all Sea-Haven-Industries repos.
#
# The label rules live HERE as the single source of truth and are written to the
# runner at execution time, so caller repos need only a short caller workflow and
# no per-repo labeler.yml.
#
# Callers trigger this on `pull_request` (NOT pull_request_target): every org repo
# is private and takes no fork PRs, so the lower-privilege event is sufficient and
# avoids the pull_request_target pwn-request surface. Because `pull_request` runs
# the workflow from the PR merge commit, the Labeler check appears on the PR that
# first adds the caller — an absent or failed Labeler check means a missing
# permission grant on the caller, not "expected" behaviour.
#
# Callers MUST grant all three permissions below. Reusable-workflow permissions can
# only be downgraded from the caller, so a caller that omits one (e.g. issues:write)
# either fails to create labels or triggers a silent startup_failure:
# permissions:
# contents: read
# pull-requests: write
# issues: write
on:
workflow_call:
permissions:
contents: read
pull-requests: write
issues: write
concurrency:
group: labeler-${{ github.event.pull_request.number || github.run_id}}
cancel-in-progress: true
jobs:
label:
runs-on: ubuntu-latest
steps:
- name: Write central label rules
run: |
mkdir -p "${{ runner.temp }}"
cat > "${{ runner.temp }}/labeler.yml" <<'EOF'
infra:
- changed-files:
- any-glob-to-any-file:
- 'lib/**'
- 'bin/**'
- 'cdk/**'
- 'cdk.json'
- 'template.yaml'
- 'template.yml'
- '**/template.yaml'
- 'samconfig.toml'
- 'infra/**'
app:
- changed-files:
- any-glob-to-any-file:
- 'src/**'
- 'functions/**'
- 'lambdas/**'
- 'api/**'
- 'services/**'
- 'web/**'
- 'mobile/**'
- 'shared/**'
content:
- changed-files:
- any-glob-to-any-file:
- '**/*.html'
- '**/*.css'
- 'assets/**'
- 'sitemap.xml'
- 'robots.txt'
ci:
- changed-files:
- any-glob-to-any-file:
- '.github/workflows/**'
- '.github/actions/**'
docs:
- changed-files:
- any-glob-to-any-file:
- '**/*.md'
dependencies:
- changed-files:
- any-glob-to-any-file:
- '**/requirements.txt'
- '**/package.json'
- '**/package-lock.json'
- '**/*.csproj'
- '**/packages.lock.json'
- '**/Directory.Packages.props'
- '**/yarn.lock'
- '**/pnpm-lock.yaml'
- '**/Podfile'
- '**/Podfile.lock'
- '.github/dependabot.yml'
tests:
- changed-files:
- any-glob-to-any-file:
# directory conventions (covers Java src/test, Ruby test/spec, etc.)
- '**/tests/**'
- '**/test/**'
- '**/spec/**'
- '**/__tests__/**'
# JS / TS
- '**/*.test.js'
- '**/*.test.jsx'
- '**/*.test.ts'
- '**/*.test.tsx'
- '**/*.spec.js'
- '**/*.spec.jsx'
- '**/*.spec.ts'
- '**/*.spec.tsx'
# Python
- '**/*_test.py'
- '**/test_*.py'
- '**/conftest.py'
# .NET
- '**/*Tests.cs'
- '**/*Test.cs'
- '**/*.Tests/**'
# Java / JVM
- '**/*Test.java'
- '**/*Tests.java'
- '**/*IT.java'
# Go
- '**/*_test.go'
# Ruby
- '**/*_spec.rb'
- '**/*_test.rb'
EOF
- uses: actions/labeler@bf12e9b00b37c5c0ca2b87b79b2daf7891dbda13 # v7.0.0
with:
repo-token: ${{ secrets.GITHUB_TOKEN }}
configuration-path: ${{ runner.temp }}/labeler.yml
sync-labels: false