Skip to content

Commit 8e28209

Browse files
authored
chore(ci): label maintainer issues by repo permission (#1116)
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com>
1 parent 230824e commit 8e28209

2 files changed

Lines changed: 12 additions & 21 deletions

File tree

‎.github/workflows/issue-triage.yml‎

Lines changed: 11 additions & 20 deletions
Original file line numberDiff line numberDiff line change
@@ -8,43 +8,34 @@ permissions:
88
issues: write
99

1010
jobs:
11-
label-mon-maintainer-issues:
11+
label-maintainer-issues:
1212
runs-on: ubuntu-latest
1313
if: github.repository_owner == 'NVIDIA'
14-
env:
15-
ORG_READ_TOKEN: ${{ secrets.ORG_READ_TOKEN }}
1614
steps:
17-
- name: Require org read token
18-
if: env.ORG_READ_TOKEN == ''
19-
run: |
20-
echo "::error::ORG_READ_TOKEN is required to check mon-maintainers membership."
21-
exit 1
22-
23-
- name: Check mon-maintainers membership
24-
id: mon-maintainer
15+
- name: Check maintainer permissions
16+
id: maintainer
2517
uses: actions/github-script@v7
2618
with:
27-
github-token: ${{ secrets.ORG_READ_TOKEN }}
2819
result-encoding: string
2920
script: |
3021
const author = context.payload.issue.user.login;
3122
3223
try {
33-
const { data } = await github.rest.teams.getMembershipForUserInOrg({
34-
org: context.repo.owner,
35-
team_slug: 'mon-maintainers',
24+
const { data } = await github.rest.repos.getCollaboratorPermissionLevel({
25+
owner: context.repo.owner,
26+
repo: context.repo.repo,
3627
username: author,
3728
});
3829
39-
if (data.state === 'active') {
40-
console.log(`${author} is an active mon-maintainers member.`);
30+
if (['admin', 'maintain', 'write'].includes(data.permission)) {
31+
console.log(`${author} has maintainer permissions: ${data.permission}.`);
4132
return 'true';
4233
}
4334
44-
console.log(`${author} has mon-maintainers membership state: ${data.state}`);
35+
console.log(`${author} does not have maintainer permissions: ${data.permission}.`);
4536
} catch (e) {
4637
if (e.status === 404) {
47-
console.log(`${author} is not a mon-maintainers member.`);
38+
console.log(`${author} is not a repository collaborator.`);
4839
return 'false';
4940
}
5041
@@ -54,7 +45,7 @@ jobs:
5445
return 'false';
5546
5647
- name: Add triage label
57-
if: steps.mon-maintainer.outputs.result == 'true'
48+
if: steps.maintainer.outputs.result == 'true'
5849
uses: actions/github-script@v7
5950
with:
6051
script: |

‎CONTRIBUTING.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -92,7 +92,7 @@ Skills connect into pipelines. Individual skill files don't describe these relat
9292
- **Policy iteration:** `openshell-cli` → `generate-sandbox-policy`
9393

9494
Workflow state labels use the `state:*` prefix, and security work uses `topic:security`. GitHub issue templates assign built-in issue types where applicable, and agent-created issues should use issue types or manual follow-up rather than type labels.
95-
New issues opened by members of the `mon-maintainers` GitHub team are automatically labeled `state:triage-needed` by the issue triage workflow.
95+
New issues opened by repository collaborators with `write`, `maintain`, or `admin` permission are automatically labeled `state:triage-needed` by the issue triage workflow.
9696

9797
## Prerequisites
9898

0 commit comments

Comments
 (0)