Add org reusable workflow callers for PRs

Wire this repo to the Sea-Haven-Industries/.github reusable labeler and
dependency-review workflows so PRs get auto-labeled and screened for
high-severity dependency advisories without per-repo config.
This commit is contained in:
Adam Moussa 2026-06-29 17:08:08 +00:00
parent a7639432e7
commit baf9e43309
2 changed files with 37 additions and 0 deletions

View file

@ -0,0 +1,15 @@
name: dependency-review
# Thin caller that runs the org-wide reusable dependency review
# (Sea-Haven-Industries/.github :: callable-dependency-review.yaml) on this
# repo's PRs, failing on high-severity advisories in added dependencies.
on:
pull_request:
permissions:
contents: read
jobs:
dependency-review:
uses: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@main

22
.github/workflows/labeler.yaml vendored Normal file
View file

@ -0,0 +1,22 @@
name: labeler
# Thin caller that runs the org-wide reusable PR labeler
# (Sea-Haven-Industries/.github :: callable-labeler.yaml) on this repo's PRs.
#
# Permissions are load-bearing: callers MUST grant all three below. Reusable-
# workflow permissions can only be downgraded from the caller, so omitting one
# (e.g. issues:write) either fails to create labels or triggers a silent
# startup_failure. `pull_request` (NOT pull_request_target) is correct here —
# the org takes no fork PRs, so the lower-privilege event is sufficient.
on:
pull_request:
permissions:
contents: read
pull-requests: write
issues: write
jobs:
label:
uses: Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml@main