build: read live PR labels in check-label action
What changed, and why it matters
This is a GitHub Actions workflow fix, not a vulnerability in the LND lightning node software itself. It changes how a CI check reads pull-request labels so that re-running a failed job sees labels added after the run started. The change adds a GitHub API call and grants the workflow read-only access to pull-request metadata. There is no direct security risk to LND users or funds.
No security action required. Reviewers may verify the new `pull-requests: read` permission is scoped only to the intended job and that the API call cannot be abused to leak repository metadata beyond labels.
Security signals we found
New GitHub API token usage (GH_TOKEN: ${{ github.token }})
New workflow permission added: pull-requests: read
CI-only change; no application code modified
Evidence from the diff
The commit updates the check-label composite action to query the live PR label list via gh api repos/{owner}/{repo}/issues/{pr}/labels instead of relying solely on the frozen github.event.pull_request.labels snapshot. It adds pull-requests: read permission to the workflow. The fallback to the event payload is retained when no PR number exists or the API call fails. This is a CI reliability/usability improvement.
Changed components
.github/actions/check-label/action.yml.github/workflows/main.ymlInspect captured patch +33 / −6
### .github/actions/check-label/action.yml
@@ -20,11 +20,36 @@ runs:
- name: Check for label
id: check
shell: bash
+ env:
+ GH_TOKEN: ${{ github.token }}
+ LABEL: ${{ inputs.label }}
+ SKIP_MESSAGE: ${{ inputs.skip-message }}
+ PR_NUMBER: ${{ github.event.pull_request.number }}
+ # Labels as seen in the event payload. This is a snapshot taken when
+ # the workflow was triggered and is only used as a fallback.
+ EVENT_LABELS: ${{ toJSON(github.event.pull_request.labels.*.name) }}
run: |
- if [[ "${{ contains(github.event.pull_request.labels.*.name, inputs.label) }}" == "true" ]]; then
- echo "::notice::${{ inputs.skip-message }}"
- echo "${{ inputs.skip-message }}" >> $GITHUB_STEP_SUMMARY
- echo "skip=true" >> $GITHUB_OUTPUT
+ # The event payload only reflects the labels that were present when
+ # the workflow was triggered. A label added afterwards (e.g. to
+ # auto-pass a check on an already running or re-run job) would never
+ # be seen. Query the API for the current label set instead so that
+ # re-running a job picks up labels added after the run kicked off.
+ labels="${EVENT_LABELS:-[]}"
+ if [[ -n "$PR_NUMBER" ]]; then
+ if live=$(gh api "repos/${GITHUB_REPOSITORY}/issues/${PR_NUMBER}/labels?per_page=100" \
+ --jq '[.[].name]'); then
+ labels="$live"
+ else
+ echo "::warning::Failed to fetch live labels for PR #${PR_NUMBER}, falling back to the event payload"
+ fi
+ fi
+
+ echo "Labels on PR #${PR_NUMBER:-<none>}: ${labels}"
+
+ if jq -e --arg l "$LABEL" 'index($l) != null' <<< "$labels" >/dev/null; then
+ echo "::notice::${SKIP_MESSAGE}"
+ echo "${SKIP_MESSAGE}" >> "$GITHUB_STEP_SUMMARY"
+ echo "skip=true" >> "$GITHUB_OUTPUT"
else
- echo "skip=false" >> $GITHUB_OUTPUT
- fi
\ No newline at end of file
+ echo "skip=false" >> "$GITHUB_OUTPUT"
+ fi
### .github/workflows/main.yml
@@ -16,6 +16,8 @@ permissions:
actions: write
# Default permission for checking out code.
contents: read
+ # Required to read the current PR labels via the API in check-label.
+ pull-requests: read
concurrency:
# Cancel any previous workflows if they are from a PR or push.Why this scored 21/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.