Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

[workshop-sync] side-quest-13-01-pr-labeler-pattern.md: invalid add-labels schema and disallowed write permission

Closed Beginner friendly
#4,045 0 comments 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

Nobody has claimed this yet.

Assessment

Difficulty
1/5
Estimated time
Under an hour
Newbie friendliness
92/100
Issue type
Bug
Clarity
Clearly specified
Activity status
Active
Tech stack
github-actions, markdown, yaml
Domain
documentation

Research direction

Open workshop/side-quest-13-01-pr-labeler-pattern.md and inspect the .github/workflows/pr-labeler.md example frontmatter. Replace the invalid add-labels field and remove the disallowed write permission as described, then run gh aw compile --validate in strict mode. Done means the example compiles with no errors or warnings.

Written by the indexing model from the issue text.

Description

documentation

Workshop file reviewed

workshop/side-quest-13-01-pr-labeler-pattern.md

Problem

The example workflow frontmatter in this file fails to compile with the current gh-aw CLI (v0.89.21) for two reasons:

  1. Invalid add-labels field limit:

    safe-outputs:
      add-labels:
        limit: 5
    

    Compiling this with gh aw compile --validate produces:

    error: Unknown property: limit. Valid fields are: allowed, allowed-repos, blocked, create-if-missing, github-app, github-token, issue-intent, issues, max, pull-requests, ...
    
  2. Disallowed write permission alongside safe-outputs:

    permissions:
      pull-requests: write
      contents: read
    

    Compiling in strict mode (the workshop's default/recommended mode) produces:

    error: strict mode: write permission 'pull-requests: write' is not allowed for security reasons. Use 'safe-outputs.create-issue', 'safe-outputs.create-pull-request', 'safe-outputs.add-comment', or 'safe-outputs.update-issue' to perform write operations safely.
    

Both errors were reproduced directly by compiling the exact snippet from the file with gh aw compile --validate.

Current correct syntax

  • The add-labels safe output uses the field max, not limit, to cap the number of labels applied.
  • permissions: should not declare pull-requests: write when safe-outputs.add-labels is used — safe-outputs performs the write on the agent's behalf and only read-level permissions are needed in the job. See https://github.github.com/gh-aw/reference/safe-outputs/

A corrected frontmatter block:

---
name: PR Labeler
on:
  pull_request:
    types: [opened, synchronize]
permissions:
  contents: read
safe-outputs:
  add-labels:
    max: 5
---

This was verified to compile successfully with gh aw compile --validate (no errors or warnings).

Suggested fix

In the .github/workflows/pr-labeler.md example inside the workshop file:

  • Replace limit: 5 with max: 5 under safe-outputs.add-labels.
  • Remove pull-requests: write from the permissions: block, keeping only contents: read.

Generated by 🔍 Workshop Sync Check · copilot · auto · 204.5 AIC · ⌖ 6.8 AIC · ⊞ 9.2K · ◷

  • expires on Oct 2, 2026, 8:58 AM UTC
Dominant language
JavaScript
Stars
52
Forks
26
Avg merge
12h 54m
Merged PRs (30d)
17

Getting set up

Open in Codespaces

Starts the project's dev container in your browser, under your own GitHub account.

  • No Dockerfile or Docker Compose file
  • No pull request template
  • No contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from githubnext/gh-aw-workshop

All issues in githubnext/gh-aw-workshop

Similar issues

More JavaScript issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.