INFRA-136: add standard labeler caller #11

Merged
amoussa1229 merged 2 commits from INFRA-136-ci-standardization into main 2026-07-08 20:36:40 +00:00

11
.github/workflows/labeler.yaml vendored Normal file
View file

@ -0,0 +1,11 @@
name: Labeler
seahaven-openswe[bot] commented 2026-07-08 20:30:37 +00:00 (Migrated from github.com)
Review

🟡 Reusable workflow pinned to floating @main

The caller workflow references Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml@main. The repo's existing ci.yaml and deploy.yaml pin the reusable workflow to a specific SHA (fd60e4c...) with a # main comment, but this new file uses a floating ref. This contradicts the established pattern and allows the callable workflow to change without a corresponding PR in this repo, causing non-reproducible builds and potentially breaking labeler permissions/silently failing on a future upstream update. The PR description says it uses @main to match the existing idiom, but the existing files actually pin to SHA. If main is the intended idiom, ci.yaml/deploy.yaml should be updated too; otherwise this file should pin to the same SHA as the others.

(Refers to line 11)


Your feedback helps Open SWE learn. React with 👍 or 👎 to tell us if this review comment was useful.

    uses: Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml@fd60e4c9041784f666ac0fdefb9bec3c7fbf5143 # main
<!-- open-swe-review-comment {"id":"f_b557002f35","file_path":".github/workflows/labeler.yaml","start_line":11,"end_line":11,"side":"RIGHT"} --> 🟡 **Reusable workflow pinned to floating @main** The caller workflow references `Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml@main`. The repo's existing `ci.yaml` and `deploy.yaml` pin the reusable workflow to a specific SHA (`fd60e4c...`) with a `# main` comment, but this new file uses a floating ref. This contradicts the established pattern and allows the callable workflow to change without a corresponding PR in this repo, causing non-reproducible builds and potentially breaking labeler permissions/silently failing on a future upstream update. The PR description says it uses `@main` to match the existing idiom, but the existing files actually pin to SHA. If `main` is the intended idiom, `ci.yaml`/`deploy.yaml` should be updated too; otherwise this file should pin to the same SHA as the others. *(Refers to line 11)* --- *Your feedback helps Open SWE learn. React with 👍 or 👎 to tell us if this review comment was useful.* ```suggestion uses: Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml@fd60e4c9041784f666ac0fdefb9bec3c7fbf5143 # main ```
on:
pull_request:
branches: [main]
permissions:
contents: read
pull-requests: write
issues: write
jobs:
label:
uses: Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml@fd60e4c9041784f666ac0fdefb9bec3c7fbf5143 # main