Commit Graph
3 Commits
Author SHA1 Message Date
Mason DaughertyandGitHub e74864ab0c fix(ci): use repo permissions instead of org membership for maintainer override (#7268)
The `require_issue_link` workflow's maintainer override (reopen PR or
remove `missing-issue-link` to bypass enforcement) has never worked. It
calls `orgs.getMembershipForUser` to verify the sender is an org member,
but `GITHUB_TOKEN` is a GitHub App installation token — not an org
member — so the endpoint always returns 403. The catch block only
handled 404, so the unhandled 403 crashed the entire job, blocking even
the normal issue-link validation from running.

## Changes
- Replace `orgs.getMembershipForUser` with
`repos.getCollaboratorPermissionLevel` in `senderIsOrgMember()` — checks
if the event sender (the user who reopened the PR or removed the label)
has write/maintain/admin access on the repo, which works with
`GITHUB_TOKEN` and is a better proxy for "maintainer" than org
membership
2026-03-24 07:03:16 +00:00
Mason Daugherty 059bf9f553 chore: split external contribution tagger into issue and PR workflows 2026-03-24 00:31:47 -04:00
af8454ec21 chore: tag + close unassigned external contributions (#7258)
amazing work by @mdrxy on this infra

---------

Co-authored-by: Mason Daugherty <github@mdrxy.com>
2026-03-24 00:08:23 -04:00