Skip to content

Use pull_request for team PR labels - #847

Merged
kiftio merged 1 commit into
mainfrom
dkift/label-team-prs-pull-request
Sep 29, 2026
Merged

kiftio merged 1 commit into
mainfrom
dkift/label-team-prs-pull-request

Conversation

@kiftio

@kiftio kiftio commented Sep 28, 2026

Copy link
Copy Markdown
Contributor

Summary

  • run the team PR labeling workflow on pull_request rather than pull_request_target
  • let the repository Actions fork-workflow approval policy gate external contributor runs

Security

This removes the privileged pull_request_target execution path for the label workflow. Fork PRs receive the normal read-only token, so they will not receive the team label; this is acceptable because the label is only needed for team PRs.

Testing

  • git diff --check

@kiftio
kiftio requested a review from a team as a code owner September 28, 2026 17:28
@github-actions github-actions Bot added the #gsd:50662 Rebase Checkout Kit on UCP label Sep 28, 2026
@kiftio
kiftio merged commit fc386fd into main Sep 29, 2026
28 checks passed
@kiftio
kiftio deleted the dkift/label-team-prs-pull-request branch September 29, 2026 08:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

#gsd:50662 Rebase Checkout Kit on UCP

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants