Repository navigation
Sandboxed agents: HTTP hooks to the app's local hook server get 403 blocked-by-allowlist from the Claude Code sandbox proxy
#61
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Label issues by OS | |
| # The bug template already REQUIRES an "Operating system" dropdown. This turns that | |
| # answer into a label so "what is broken on Windows" is a query instead of a read. | |
| on: | |
| issues: | |
| types: [opened, edited, reopened] | |
| permissions: | |
| issues: write | |
| jobs: | |
| apply-os-label: | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 5 | |
| steps: | |
| - name: Apply OS label from the issue form | |
| uses: actions/github-script@v7 | |
| with: | |
| script: | | |
| const issue = context.payload.issue; | |
| const body = issue.body || ''; | |
| const match = body.match(/^###\s+Operating system\s*\n+\s*(.+?)\s*$/m); | |
| if (!match) { | |
| core.info('No "Operating system" field on this issue. Skipping.'); | |
| return; | |
| } | |
| // Our dropdown offers "macOS (Apple Silicon)", "macOS (Intel)", "Windows", | |
| // "Linux", so match on PREFIX. An exact-match port would silently do | |
| // nothing for both macOS options. | |
| const answer = match[1].trim().toLowerCase(); | |
| const managed = ['os:macos', 'os:windows', 'os:linux']; | |
| let desired = null; | |
| if (answer.startsWith('macos')) desired = 'os:macos'; | |
| else if (answer.startsWith('windows')) desired = 'os:windows'; | |
| else if (answer.startsWith('linux')) desired = 'os:linux'; | |
| if (!desired) { | |
| core.info(`No OS label configured for "${answer}". Skipping.`); | |
| return; | |
| } | |
| const current = (issue.labels || []).map(l => (typeof l === 'string' ? l : l.name)); | |
| // Drop any stale OS label first, so an edited issue does not keep both. | |
| for (const stale of managed.filter(l => l !== desired && current.includes(l))) { | |
| await github.rest.issues.removeLabel({ | |
| ...context.repo, issue_number: issue.number, name: stale, | |
| }).catch(e => core.info(`Could not remove ${stale}: ${e.message}`)); | |
| } | |
| if (current.includes(desired)) { | |
| core.info(`${desired} already applied.`); | |
| return; | |
| } | |
| await github.rest.issues.addLabels({ | |
| ...context.repo, issue_number: issue.number, labels: [desired], | |
| }); | |
| core.info(`Applied ${desired}.`); |