Skip to content

ci: stop labelling fork pull requests in the PR title check - #207

Merged
jplanckeel merged 1 commit into
BananaOps:mainfrom
TartanLeGrand:ci/pr-title-fork-prs
Oct 1, 2026
Merged

jplanckeel merged 1 commit into
BananaOps:mainfrom
TartanLeGrand:ci/pr-title-fork-prs

Conversation

@TartanLeGrand

@TartanLeGrand TartanLeGrand commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Why

validate-pr-title fails on every pull request opened from a fork (#200, #201, #202, #206) with Resource not accessible by integration, even when the title is valid. The action validates the title, then adds type and scope labels; a pull_request run triggered from a fork only gets a read-only GITHUB_TOKEN, so the label call is refused and the job fails.

What

  • add_label and add_scope_label are enabled only when the head repository is this repository. Fork pull requests are still validated, just not labelled. The action compares the input to the string false and skips the label calls.
  • Explicit permissions: contents: read at the workflow level, pull-requests: write only on the job (needed for the labels).
  • Action pinned to the commit SHA of 1.5.2 instead of the mutable tag.

pull_request_target would restore labels on fork PRs, but it hands a write token to runs triggered by external contributors; not worth it for labels.

Check

This pull request comes from a fork and runs the modified workflow: validate-pr-title should be green here.

A pull request from a fork runs with a read-only token, so the label step
failed with "Resource not accessible by integration" and turned the check
red even for a valid title. Labels are now only added for pull requests
opened from a branch of this repository.

Also declares least-privilege permissions and pins the action to a commit
SHA.
@jplanckeel
jplanckeel merged commit c9edcd8 into BananaOps:main Oct 1, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants