* fix: trust community PRs when maintainer pushes to the branch When a maintainer merges main into a community PR branch, the new SHA invalidates the run-ci label timing check because the label was added before the new push. This fix adds a check to trust the PR if the person who pushed the latest commit has write access. This handles the case where a maintainer: - Merges main into a community PR to resolve conflicts - Pushes any changes to help the contributor The security model is maintained because: - Only users with write access can trigger this trust - The maintainer has reviewed the code by pushing to it Co-Authored-By: anik@cal.com <adhabal2002@gmail.com> * fix: skip stale label check on workflow re-runs Instead of implicitly trusting maintainer pushes (which could be just a sync action without code review), use github.run_attempt to detect re-runs. If run_attempt > 1, it means the workflow was explicitly re-triggered (via run-ci.yml or manual re-run), so we skip the stale label check. This avoids the need to remove and re-add the 'run-ci' label after syncing a community PR with main, while keeping the explicit approval flow intact. Co-Authored-By: anik@cal.com <adhabal2002@gmail.com> * Simplify comment about re-runs in PR workflow --------- Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> Co-authored-by: Keith Williams <keithwillcode@gmail.com>