From 3e6c3894de1f66ec8dbbbebe3e86a9af0d85b8d5 Mon Sep 17 00:00:00 2001 From: Mick Vleeshouwer Date: Sat, 5 Sep 2026 23:00:58 +0000 Subject: [PATCH] ci: Fix automatic labeling for fork pull requests --- .github/workflows/release-drafter.yml | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/.github/workflows/release-drafter.yml b/.github/workflows/release-drafter.yml index 508272c1..a4ee3855 100644 --- a/.github/workflows/release-drafter.yml +++ b/.github/workflows/release-drafter.yml @@ -4,7 +4,8 @@ on: push: branches: - main - pull_request: + # Fork PRs need a base-repository token to apply labels. + pull_request_target: types: [opened, reopened, synchronize, edited] permissions: @@ -26,8 +27,9 @@ jobs: # Apply Conventional-Commit labels from the PR title (PRs only). # The autolabeler is a separate sub-action; the main action above only drafts # releases and does not apply labels. + # Keep this privileged job free of PR code checkout or execution. autolabel: - if: github.event_name == 'pull_request' + if: github.event_name == 'pull_request_target' runs-on: ubuntu-latest permissions: contents: read