Port or remove the nonfunctional Pull Request Triage workflow #4
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Problem
.github/workflows/pull-request-triage.ymlis present and discovered, but its jobs have never executed successfully on Guksu's Forgejo infrastructure.The repository's only PR produced Actions run 3. Both
Auto-labelandPull Request template checkwere cancelled at0s. There are no successful triage runs in the current 37-run history.Evidence
runs-on: ubuntu-latest.[self-hosted, linux, x64, nix]host labels.actions/github-script,actions/labeler,secrets.GITHUB_TOKEN, and GitHub REST client behavior that has not been validated against the live Forgejo instance.pull_request_targetwith write permission. That is a sensitive trust boundary even though the current workflow correctly avoids checking out PR code.Proposed resolution
Port the triage behavior to a small Guksu-owned Forgejo workflow, or remove it if automatic triage is not useful.
A replacement should:
pull_request_targetboundary: do not check out or execute untrusted PR code with a write-capable token.Acceptance criteria
.github/labeler.yml, or that feature is deliberately removed.