[workshop-sync] side-quest-13-01-pr-labeler-pattern.md: invalid add-labels schema and disallowed write permission
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 1/5
- Estimated time
- Under an hour
- Newbie friendliness
- 92/100
- Issue type
- Bug
- Clarity
- Clearly specified
- Activity status
- Active
- Tech stack
- github-actions, markdown, yaml
- Domain
- documentation
Research direction
Open workshop/side-quest-13-01-pr-labeler-pattern.md and inspect the .github/workflows/pr-labeler.md example frontmatter. Replace the invalid add-labels field and remove the disallowed write permission as described, then run gh aw compile --validate in strict mode. Done means the example compiles with no errors or warnings.
Written by the indexing model from the issue text.
Description
Workshop file reviewed
workshop/side-quest-13-01-pr-labeler-pattern.md
Problem
The example workflow frontmatter in this file fails to compile with the current gh-aw CLI (v0.89.21) for two reasons:
-
Invalid
add-labelsfieldlimit:safe-outputs: add-labels: limit: 5Compiling this with
gh aw compile --validateproduces:error: Unknown property: limit. Valid fields are: allowed, allowed-repos, blocked, create-if-missing, github-app, github-token, issue-intent, issues, max, pull-requests, ... -
Disallowed write permission alongside
safe-outputs:permissions: pull-requests: write contents: readCompiling in strict mode (the workshop's default/recommended mode) produces:
error: strict mode: write permission 'pull-requests: write' is not allowed for security reasons. Use 'safe-outputs.create-issue', 'safe-outputs.create-pull-request', 'safe-outputs.add-comment', or 'safe-outputs.update-issue' to perform write operations safely.
Both errors were reproduced directly by compiling the exact snippet from the file with gh aw compile --validate.
Current correct syntax
- The
add-labelssafe output uses the fieldmax, notlimit, to cap the number of labels applied. permissions:should not declarepull-requests: writewhensafe-outputs.add-labelsis used —safe-outputsperforms the write on the agent's behalf and only read-level permissions are needed in the job. See https://github.github.com/gh-aw/reference/safe-outputs/
A corrected frontmatter block:
---
name: PR Labeler
on:
pull_request:
types: [opened, synchronize]
permissions:
contents: read
safe-outputs:
add-labels:
max: 5
---
This was verified to compile successfully with gh aw compile --validate (no errors or warnings).
Suggested fix
In the .github/workflows/pr-labeler.md example inside the workshop file:
- Replace
limit: 5withmax: 5undersafe-outputs.add-labels. - Remove
pull-requests: writefrom thepermissions:block, keeping onlycontents: read.
Generated by 🔍 Workshop Sync Check · copilot · auto · 204.5 AIC · ⌖ 6.8 AIC · ⊞ 9.2K · ◷
- expires on Oct 2, 2026, 8:58 AM UTC
- Dominant language
- JavaScript
- Stars
- 52
- Forks
- 26
- Avg merge
- 12h 54m
- Merged PRs (30d)
- 17
Getting set up
Starts the project's dev container in your browser, under your own GitHub account.
- No Dockerfile or Docker Compose file
- No pull request template
- No contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from githubnext/gh-aw-workshop
-
documentation
Difficulty 1/5 Under an hour Newbie friendliness 91/100
githubnext/gh-aw-workshop#4458 ·
Maintainers usually reply within 1 day
-
feedback simulation workshop
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
githubnext/gh-aw-workshop#4456 ·
Maintainers usually reply within 1 day
-
feedback simulation workshop
Difficulty 2/5 1-3 hours Newbie friendliness 73/100
githubnext/gh-aw-workshop#4455 ·
Maintainers usually reply within 1 day
-
feedback simulation workshop
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
githubnext/gh-aw-workshop#4454 ·
Maintainers usually reply within 1 day
-
documentation
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
githubnext/gh-aw-workshop#4451 ·
Maintainers usually reply within 1 day
All issues in githubnext/gh-aw-workshop
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
dusk-network/exu#17 ·
-
Difficulty 1/5 Under an hour Newbie friendliness 88/100
jspreadsheet/ce#1809 ·
-
Add: CartoonitoOpencheck:failed feeds:add
Difficulty 2/5 1-3 hours Newbie friendliness 63/100
iptv-org/database#37390 · 1 comment ·
Maintainers usually reply within 9 days
-
bug: directory index route root priority is overwritten when wildcard is falsePossibly taken @TalhaHunter101 claimed this today. Open
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
fastify/fastify-static#617 ·
-
bug confirmed css v6
Difficulty 2/5 1-3 hours Newbie friendliness 66/100
Maintainers usually reply within 1 day