Files
penpot/.github/workflows/auto-label.yml
T
David Barragán Merino b2ea46a71a 🔧 Use client-id instead of app-id in auto-label workflow
actions/create-github-app-token v3 deprecates the app-id input in
favour of client-id. Switch to the new TRIAGE_APP_CLIENT_ID secret.

Signed-off-by: David Barragán Merino <david.barragan@kaleidos.net>
2026-10-05 13:11:08 +02:00

87 lines
3.3 KiB
YAML

name: Auto Label and Add to Project
# pull_request_target is required so the GitHub App secrets are available
# for PRs from forks. It is safe here: the job never checks out or runs PR
# code, it only reads ids from the event payload.
on:
issues:
types: [opened]
pull_request_target:
types: [opened]
permissions: {}
jobs:
triage:
# Dependabot PRs are labelled by dependabot.yml and do not need triage.
if: github.actor != 'dependabot[bot]'
runs-on: ubuntu-latest
steps:
- name: Generate GitHub App token
id: triage-app-token
uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0
with:
client-id: ${{ secrets.TRIAGE_APP_CLIENT_ID }}
private-key: ${{ secrets.TRIAGE_APP_PRIVATE_KEY }}
# No owner/repositories: the token is scoped to this repository.
# Organization permissions (the project board) still apply.
permission-issues: write
permission-organization-projects: write
- name: Process Issue or PR
uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
with:
github-token: ${{ steps.triage-app-token.outputs.token }}
script: |
// === 1. CONFIGURATION ===
const PROJECT_NUMBER = 8; // <--- Replace with your project board number
const IS_ORG = true; // <--- Set to false if this is a personal project, true if an organization
const OWNER = context.repo.owner;
const REPO = context.repo.repo;
const issueNumber = context.issue.number;
const isPR = !!context.payload.pull_request;
const contentId = isPR ? context.payload.pull_request.node_id : context.payload.issue.node_id;
// Define your labels here
const labelToApply = 'needs triage';
// === 2. APPLY THE LABEL ===
console.log(`Applying label "${labelToApply}" to ${isPR ? 'PR' : 'Issue'} #${issueNumber}...`);
await github.rest.issues.addLabels({
issue_number: issueNumber,
owner: OWNER,
repo: REPO,
labels: [labelToApply]
});
// === 3. ADD TO PROJECT BOARD ===
console.log(`Fetching Project #${PROJECT_NUMBER} ID...`);
const projectQuery = `
query($owner: String!, $number: Int!) {
${IS_ORG ? 'organization' : 'user'}(login: $owner) {
projectV2(number: $number) {
id
}
}
}
`;
const projectRes = await github.graphql(projectQuery, { owner: OWNER, number: PROJECT_NUMBER });
const projectId = IS_ORG ? projectRes.organization.projectV2.id : projectRes.user.projectV2.id;
console.log(`Adding item to project board...`);
const addToProjectMutation = `
mutation($projectId: ID!, $contentId: ID!) {
addProjectV2ItemById(input: {projectId: $projectId, contentId: $contentId}) {
item {
id
}
}
}
`;
await github.graphql(addToProjectMutation, { projectId, contentId });
console.log("Automation successfully completed!");