From e869f0af06f5d9d453d0040fecbfe09a8f8d493d Mon Sep 17 00:00:00 2001 From: lindicaphxag-tech Date: Fri, 18 Sep 2026 14:17:39 +0800 Subject: [PATCH] Fix label workflow for fork pull requests --- .github/tests/test_label_pr_workflow.js | 19 ++++++++++++++++ .github/workflows/label-pr.yml | 29 ++----------------------- 2 files changed, 21 insertions(+), 27 deletions(-) create mode 100644 .github/tests/test_label_pr_workflow.js diff --git a/.github/tests/test_label_pr_workflow.js b/.github/tests/test_label_pr_workflow.js new file mode 100644 index 000000000000..56384ceb952c --- /dev/null +++ b/.github/tests/test_label_pr_workflow.js @@ -0,0 +1,19 @@ +// Copyright (c) Microsoft. All rights reserved. + +const { describe, it } = require('node:test'); +const assert = require('node:assert/strict'); +const { readFileSync } = require('node:fs'); +const { join } = require('node:path'); + +const workflowPath = join(__dirname, '..', 'workflows', 'label-pr.yml'); +const workflow = readFileSync(workflowPath, 'utf8'); + +describe('Label pull request workflow', () => { + it('uses the pull request token without the protected GitHub App environment', () => { + assert.match(workflow, /^on: \[pull_request_target\]$/m); + assert.doesNotMatch(workflow, /^\s+environment: github-app-auth$/m); + assert.match(workflow, /^\s+pull-requests: write$/m); + assert.doesNotMatch(workflow, /github-app-token/); + assert.match(workflow, /repo-token: \$\{\{ github\.token \}\}/); + }); +}); diff --git a/.github/workflows/label-pr.yml b/.github/workflows/label-pr.yml index f751f93a56ba..cac89e7f5b97 100644 --- a/.github/workflows/label-pr.yml +++ b/.github/workflows/label-pr.yml @@ -11,36 +11,11 @@ on: [pull_request_target] jobs: add_label: runs-on: ubuntu-latest - environment: github-app-auth permissions: contents: read - id-token: write + pull-requests: write steps: - - name: Checkout GitHub automation - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - with: - ref: ${{ github.event.pull_request.base.sha }} - sparse-checkout: .github/actions/github-app-token - fetch-depth: 1 - persist-credentials: false - - - name: Get GitHub automation token - id: github-auth - uses: ./.github/actions/github-app-token - with: - mode: ${{ vars.GH_APP_AUTH_MODE }} - azure-client-id: ${{ secrets.GH_APP_AZURE_CLIENT_ID }} - azure-tenant-id: ${{ secrets.GH_APP_AZURE_TENANT_ID }} - azure-subscription-id: ${{ secrets.GH_APP_AZURE_SUBSCRIPTION_ID }} - key-vault-name: ${{ secrets.GH_APP_KEY_VAULT_NAME }} - key-name: ${{ secrets.GH_APP_KEY_NAME }} - github-app-client-id: ${{ secrets.GH_APP_CLIENT_ID }} - github-app-installation-id: ${{ secrets.GH_APP_INSTALLATION_ID }} - repository: ${{ github.repository }} - permission-profile: pull-requests - fallback-token: ${{ secrets.GH_ACTIONS_PR_WRITE }} - - uses: actions/labeler@b8dd2d9be0f68b860e7dae5dae7d772984eacd6d # v6.2.0 with: - repo-token: ${{ steps.github-auth.outputs.token }} + repo-token: ${{ github.token }}