.github/.github/workflows/callable-labeler.yaml
Adam Moussa af0f002e14
Some checks failed
ci / ci / ci (push) Waiting to run
Release on reusable change / version (push) Has been cancelled
Release on reusable change / release (push) Has been cancelled
ci: expand labeler globs and skip dependabot pr policy (PLAT-107) (#124)
* ci: expand labeler globs and skip dependabot pr policy

.NET product paths never matched app, so backend PRs stayed unlabeled. Dependabot PRs still ran commit-subject and pin checks on generated titles. Skip those PRs in the reusable policy job.

* fix(labeler): match nested elastic beanstalk config paths

Root-only .ebextensions and .platform globs miss api/.ebextensions in monorepos. Mirror the Dockerfile nested form.
2026-08-21 12:42:28 -04:00

141 lines
4.9 KiB
YAML

name: Labeler
# Reusable PR auto-labeler for all Sea-Haven-Industries repos.
#
# The label rules live HERE as the single source of truth and are written to the
# runner at execution time, so caller repos need only a short caller workflow and
# no per-repo labeler.yml.
#
# Callers trigger this on `pull_request` (NOT pull_request_target): every org repo
# is private and takes no fork PRs, so the lower-privilege event is sufficient and
# avoids the pull_request_target pwn-request surface. Because `pull_request` runs
# the workflow from the PR merge commit, the Labeler check appears on the PR that
# first adds the caller — an absent or failed Labeler check means a missing
# permission grant on the caller, not "expected" behaviour.
#
# Callers MUST grant all three permissions below. Reusable-workflow permissions can
# only be downgraded from the caller, so a caller that omits one (e.g. issues:write)
# either fails to create labels or triggers a silent startup_failure:
# permissions:
# contents: read
# pull-requests: write
# issues: write
on:
workflow_call:
permissions:
contents: read
pull-requests: write
issues: write
concurrency:
group: labeler-${{ github.event.pull_request.number || github.run_id}}
cancel-in-progress: true
jobs:
label:
runs-on: ubuntu-latest
steps:
- name: Write central label rules
run: |
mkdir -p "${{ runner.temp }}"
cat > "${{ runner.temp }}/labeler.yml" <<'EOF'
infra:
- changed-files:
- any-glob-to-any-file:
- 'lib/**'
- 'bin/**'
- 'cdk/**'
- 'cdk.json'
- 'template.yaml'
- 'template.yml'
- '**/template.yaml'
- 'samconfig.toml'
- 'infra/**'
- 'Dockerfile'
- '**/Dockerfile'
- '.ebextensions/**'
- '**/.ebextensions/**'
- '.platform/**'
- '**/.platform/**'
app:
- changed-files:
- any-glob-to-any-file:
- 'src/**'
- 'functions/**'
- 'lambdas/**'
- 'api/**'
- 'services/**'
- 'web/**'
- 'mobile/**'
- 'shared/**'
- '**/*.cs'
- '**/*.cshtml'
- '**/*.razor'
content:
- changed-files:
- any-glob-to-any-file:
- '**/*.html'
- '**/*.css'
- 'assets/**'
- 'sitemap.xml'
- 'robots.txt'
ci:
- changed-files:
- any-glob-to-any-file:
- '.github/workflows/**'
- '.github/actions/**'
docs:
- changed-files:
- any-glob-to-any-file:
- '**/*.md'
dependencies:
- changed-files:
- any-glob-to-any-file:
- '**/requirements.txt'
- '**/package.json'
- '**/package-lock.json'
- '**/*.csproj'
- '**/packages.lock.json'
- '**/Directory.Packages.props'
- '**/yarn.lock'
- '**/pnpm-lock.yaml'
- '**/Podfile'
- '**/Podfile.lock'
- '.github/dependabot.yml'
tests:
- changed-files:
- any-glob-to-any-file:
- '**/tests/**'
- '**/test/**'
- '**/spec/**'
- '**/__tests__/**'
- 'e2e/**'
- '**/e2e/**'
- '**/*.test.js'
- '**/*.test.jsx'
- '**/*.test.ts'
- '**/*.test.tsx'
- '**/*.spec.js'
- '**/*.spec.jsx'
- '**/*.spec.ts'
- '**/*.spec.tsx'
- '**/*_test.py'
- '**/test_*.py'
- '**/conftest.py'
- '**/*Tests.cs'
- '**/*Test.cs'
- '**/*.Tests/**'
- '**/*Test.java'
- '**/*Tests.java'
- '**/*IT.java'
- '**/*_test.go'
- '**/*_spec.rb'
- '**/*_test.rb'
EOF
- uses: actions/labeler@bf12e9b00b37c5c0ca2b87b79b2daf7891dbda13 # v7.0.0
with:
repo-token: ${{ secrets.GITHUB_TOKEN }}
configuration-path: ${{ runner.temp }}/labeler.yml
sync-labels: false