ActionRank

Require Labels

Actively maintained

mheap/github-action-required-labels · MIT

Fail the build if/unless a certain combination of labels are applied to a pull request

116 starsLast commit 2 months agoLatest v5.6.0
C
60
/ 100
Security 42Maintenance 76Popularity 42Reliability 96

Security signals

OpenSSF Scorecard3.7 / 10
SECURITY.md presentNo
Immutable releasesNot enabled
Known vulnerabilitiesNone on record

How to use it safely

Recommended: pin to commit SHA
uses: mheap/github-action-required-labels@23e10fde7e062233401931a0eece796cd9bf3177 # v5.6.0

Mutable tags like v5.6.0 can be rewritten to point at malicious commits. Pinning to the full commit SHA is the only reference GitHub guarantees immutable.

Full workflow example
steps:
  - uses: mheap/github-action-required-labels@23e10fde7e062233401931a0eece796cd9bf3177 # v5.6.0

Score breakdown

Security (35%)42
Popularity (20%)42
Maintenance (30%)76
Reliability (15%)96

Add this badge to your README

ActionRank grade badge for Require Labels
Markdown
[![ActionRank](https://actionrank.dev/api/badge/mheap-github-action-required-labels)](https://actionrank.dev/actions/mheap-github-action-required-labels)
HTML version
HTML
<a href="https://actionrank.dev/actions/mheap-github-action-required-labels"><img src="https://actionrank.dev/api/badge/mheap-github-action-required-labels" alt="ActionRank score"></a>

Free to use, no attribution required — the badge updates itself as the score changes. How badges work

Get alerts for Require Labels

We'll email you only if Require Labels becomes abandoned or a new advisory is published. Unsubscribe any time. How we handle your address