name: Auto Label PRs on: pull_request_target: types: [opened, synchronize, reopened] permissions: contents: read pull-requests: write jobs: label: runs-on: ubuntu-latest steps: # Step 1: Add category labels based on file changes - name: Auto-label by file changes uses: actions/labeler@v5 with: repo-token: "${{ secrets.GITHUB_TOKEN }}" configuration-path: .github/labeler.yml sync-labels: false # Step 2: Add run-ci label for authorized users (only on opened/reopened) - name: Check user permission if: github.event.action == 'opened' || github.event.action == 'reopened' id: checkAccess uses: actions-cool/check-user-permission@v2 with: require: write username: ${{ github.triggering_actor }} env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} - name: Add run-ci label if: (github.event.action == 'opened' || github.event.action == 'reopened') && steps.checkAccess.outputs.require-result == 'true' uses: actions/github-script@v7 with: github-token: ${{ secrets.GH_PAT_FOR_PULL_REQUEST }} script: | github.rest.issues.addLabels({ owner: context.repo.owner, repo: context.repo.repo, issue_number: context.issue.number, labels: ['run-ci'] })