Port or remove the nonfunctional Pull Request Triage workflow #4

Open
opened 2026-08-05 08:36:55 -04:00 by fidget · 0 comments
Owner

Problem

.github/workflows/pull-request-triage.yml is present and discovered, but its jobs have never executed successfully on Guksu's Forgejo infrastructure.

The repository's only PR produced Actions run 3. Both Auto-label and Pull Request template check were cancelled at 0s. There are no successful triage runs in the current 37-run history.

Evidence

  • Both jobs request runs-on: ubuntu-latest.
  • Guksu's active runner only advertises [self-hosted, linux, x64, nix] host labels.
  • Auto-labeling depends on actions/github-script, actions/labeler, secrets.GITHUB_TOKEN, and GitHub REST client behavior that has not been validated against the live Forgejo instance.
  • The trigger is pull_request_target with write permission. That is a sensitive trust boundary even though the current workflow correctly avoids checking out PR code.

Proposed resolution

Port the triage behavior to a small Guksu-owned Forgejo workflow, or remove it if automatic triage is not useful.

A replacement should:

  1. Use Guksu's self-hosted runner labels.
  2. Use Forgejo-compatible label and PR APIs.
  3. Preserve the base-controlled pull_request_target boundary: do not check out or execute untrusted PR code with a write-capable token.
  4. Keep title/branch labels, path labels, and template validation independently testable so one unavailable action does not disable every triage function.

Acceptance criteria

  • A real PR open/update event schedules the workflow on an available runner.
  • Feature/bugfix title or branch classification updates Forgejo labels correctly.
  • Path-based labels are applied from .github/labeler.yml, or that feature is deliberately removed.
  • Template checks produce a clear pass/fail result for non-member contributors.
  • No PR-controlled code or configuration executes with the write-capable token.
  • The tested run reaches an explicit terminal result and leaves an auditable label/check outcome.
## Problem `.github/workflows/pull-request-triage.yml` is present and discovered, but its jobs have never executed successfully on Guksu's Forgejo infrastructure. The repository's only PR produced [Actions run 3](https://git.birdintra.net/fidget/Guksu-Motor/actions/runs/3). Both `Auto-label` and `Pull Request template check` were cancelled at `0s`. There are no successful triage runs in the current 37-run history. ## Evidence - Both jobs request `runs-on: ubuntu-latest`. - Guksu's active runner only advertises `[self-hosted, linux, x64, nix]` host labels. - Auto-labeling depends on `actions/github-script`, `actions/labeler`, `secrets.GITHUB_TOKEN`, and GitHub REST client behavior that has not been validated against the live Forgejo instance. - The trigger is `pull_request_target` with write permission. That is a sensitive trust boundary even though the current workflow correctly avoids checking out PR code. ## Proposed resolution Port the triage behavior to a small Guksu-owned Forgejo workflow, or remove it if automatic triage is not useful. A replacement should: 1. Use Guksu's self-hosted runner labels. 2. Use Forgejo-compatible label and PR APIs. 3. Preserve the base-controlled `pull_request_target` boundary: do not check out or execute untrusted PR code with a write-capable token. 4. Keep title/branch labels, path labels, and template validation independently testable so one unavailable action does not disable every triage function. ## Acceptance criteria - [ ] A real PR open/update event schedules the workflow on an available runner. - [ ] Feature/bugfix title or branch classification updates Forgejo labels correctly. - [ ] Path-based labels are applied from `.github/labeler.yml`, or that feature is deliberately removed. - [ ] Template checks produce a clear pass/fail result for non-member contributors. - [ ] No PR-controlled code or configuration executes with the write-capable token. - [ ] The tested run reaches an explicit terminal result and leaves an auditable label/check outcome.
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
fidget/Guksu-Motor#4
No description provided.