From 4c6bba04ae8b71b5add298afbdae50b387300bd6 Mon Sep 17 00:00:00 2001 From: umignon Date: Mon, 28 Sep 2026 10:24:11 +0200 Subject: [PATCH] ci: stop labelling fork pull requests in the PR title check A pull request from a fork runs with a read-only token, so the label step failed with "Resource not accessible by integration" and turned the check red even for a valid title. Labels are now only added for pull requests opened from a branch of this repository. Also declares least-privilege permissions and pins the action to a commit SHA. --- .github/workflows/conventional-commit.yml | 15 ++++++++++++--- 1 file changed, 12 insertions(+), 3 deletions(-) diff --git a/.github/workflows/conventional-commit.yml b/.github/workflows/conventional-commit.yml index 10981c4..bf1149a 100644 --- a/.github/workflows/conventional-commit.yml +++ b/.github/workflows/conventional-commit.yml @@ -5,13 +5,22 @@ on: # yamllint disable-line rule:truthy pull_request: types: [opened, synchronize, reopened, edited] +permissions: + contents: read + jobs: validate-pr-title: runs-on: ubuntu-latest + permissions: + contents: read + pull-requests: write steps: - name: PR Conventional Commit Validation - uses: ytanikin/pr-conventional-commits@1.5.2 + uses: ytanikin/pr-conventional-commits@639145d78959c53c43112365837e3abd21ed67c1 # 1.5.2 with: task_types: '["feat","fix","docs","test","ci","refactor","perf","chore","revert"]' - add_label: true - add_scope_label: true + # A pull request from a fork gets a read-only token: labelling it + # fails the job even when the title is valid. Only label pull + # requests opened from a branch of this repository. + add_label: ${{ github.event.pull_request.head.repo.full_name == github.repository }} + add_scope_label: ${{ github.event.pull_request.head.repo.full_name == github.repository }}