Repository navigation
Python: [Feature]: A deterministic pre-execution verification middleware for agent actions — AgentDojo v2.2 re-run: ASR=0 / FP=0 (open artifacts, full fix-cycle trajectory inside) #3696
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Label issues | |
| on: | |
| issues: | |
| types: | |
| - reopened | |
| - opened | |
| jobs: | |
| label_issues: | |
| name: "Issue: add labels" | |
| if: ${{ github.event.action == 'opened' || github.event.action == 'reopened' }} | |
| runs-on: ubuntu-latest | |
| environment: github-app-auth | |
| permissions: | |
| contents: read | |
| id-token: write | |
| issues: write | |
| steps: | |
| - name: Checkout GitHub automation | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| sparse-checkout: | | |
| .github/actions/github-app-token | |
| .github/scripts/check_team_membership.js | |
| .github/scripts/set_missing_issue_type.js | |
| fetch-depth: 1 | |
| persist-credentials: false | |
| - name: Get GitHub automation token | |
| id: github-auth | |
| uses: ./.github/actions/github-app-token | |
| with: | |
| mode: ${{ vars.GH_APP_AUTH_MODE }} | |
| azure-client-id: ${{ secrets.GH_APP_AZURE_CLIENT_ID }} | |
| azure-tenant-id: ${{ secrets.GH_APP_AZURE_TENANT_ID }} | |
| azure-subscription-id: ${{ secrets.GH_APP_AZURE_SUBSCRIPTION_ID }} | |
| key-vault-name: ${{ secrets.GH_APP_KEY_VAULT_NAME }} | |
| key-name: ${{ secrets.GH_APP_KEY_NAME }} | |
| github-app-client-id: ${{ secrets.GH_APP_CLIENT_ID }} | |
| github-app-installation-id: ${{ secrets.GH_APP_INSTALLATION_ID }} | |
| repository: ${{ github.repository }} | |
| fallback-token: ${{ secrets.GH_ACTIONS_PR_WRITE }} | |
| - uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 | |
| with: | |
| github-token: ${{ steps.github-auth.outputs.token }} | |
| script: | | |
| // Get the issue body and title | |
| const body = context.payload.issue.body | |
| let title = context.payload.issue.title | |
| // Define the labels array | |
| let labels = [] | |
| const checkTeamMembership = require('./.github/scripts/check_team_membership.js') | |
| const { isTeamMember } = await checkTeamMembership({ | |
| github, | |
| context, | |
| core, | |
| teamSlug: process.env.TEAM_NAME, | |
| issueNumber: context.issue.number, | |
| }) | |
| // Only add triage label if the author is not in the team | |
| if (!isTeamMember) { | |
| labels.push("triage") | |
| } | |
| // Helper function to extract field value from issue form body | |
| // Issue forms format fields as: ### Field Name\n\nValue | |
| function getFormFieldValue(body, fieldName) { | |
| if (!body) return null | |
| const regex = new RegExp(`###\\s*${fieldName}\\s*\\n\\n([^\\n#]+)`, 'i') | |
| const match = body.match(regex) | |
| return match ? match[1].trim() : null | |
| } | |
| // Check for language from issue form dropdown first | |
| const languageField = getFormFieldValue(body, 'Language') | |
| let languageLabelAdded = false | |
| if (languageField) { | |
| if (languageField === 'Python') { | |
| labels.push("python") | |
| languageLabelAdded = true | |
| } else if (languageField === '.NET') { | |
| labels.push(".NET") | |
| languageLabelAdded = true | |
| } | |
| // 'None / Not Applicable' - don't add any language label | |
| } | |
| // Fallback: Check if the body or the title contains the word 'python' (case-insensitive) | |
| // Only if language wasn't already determined from the form field | |
| if (!languageLabelAdded) { | |
| if ((body != null && body.match(/python/i)) || (title != null && title.match(/python/i))) { | |
| // Add the 'python' label to the array | |
| labels.push("python") | |
| } | |
| // Check if the body or the title contains the words 'dotnet', '.net', 'c#' or 'csharp' (case-insensitive) | |
| if ((body != null && body.match(/\.net/i)) || (title != null && title.match(/\.net/i)) || | |
| (body != null && body.match(/dotnet/i)) || (title != null && title.match(/dotnet/i)) || | |
| (body != null && body.match(/C#/i)) || (title != null && title.match(/C#/i)) || | |
| (body != null && body.match(/csharp/i)) || (title != null && title.match(/csharp/i))) { | |
| // Add the '.NET' label to the array | |
| labels.push(".NET") | |
| } | |
| } | |
| // Check for issue type from issue form dropdown | |
| const issueTypeField = getFormFieldValue(body, 'Type of Issue') | |
| if (issueTypeField) { | |
| if (issueTypeField === 'Feature Request') { | |
| labels.push("enhancement") | |
| } else if (issueTypeField === 'Question') { | |
| labels.push("question") | |
| } | |
| } | |
| // Add the labels to the issue (only if there are labels to add) | |
| if (labels.length > 0) { | |
| await github.rest.issues.addLabels({ | |
| issue_number: context.issue.number, | |
| owner: context.repo.owner, | |
| repo: context.repo.repo, | |
| labels: labels | |
| }); | |
| } | |
| env: | |
| TEAM_NAME: ${{ secrets.DEVELOPER_TEAM }} | |
| # Run after labeling so fallback API failures do not prevent labels. | |
| # Use the app token so assigning a type can trigger the triage workflow. | |
| - name: Set missing issue type | |
| uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 | |
| with: | |
| github-token: ${{ steps.github-auth.outputs.token }} | |
| script: | | |
| const setMissingIssueType = require('./.github/scripts/set_missing_issue_type.js'); | |
| await setMissingIssueType({ github, context, core }); |