Skip to content

ci(github): use app token for dependabot merges#49

Merged
ncipollina merged 2 commits into
mainfrom
ci/dependabot-app-token
Jul 22, 2026
Merged

ci(github): use app token for dependabot merges#49
ncipollina merged 2 commits into
mainfrom
ci/dependabot-app-token

Conversation

@ncipollina

Copy link
Copy Markdown
Contributor

Summary

Updates the Dependabot auto-merge workflow to use the LayeredCraft GitHub App token for approving and enabling auto-merge. This avoids using GITHUB_TOKEN for the merge operation so downstream workflows can run after Dependabot auto-merged changes land on main.

Changes

  • Adds a SHA-pinned actions/create-github-app-token step for semver patch/minor Dependabot PRs.
  • Uses the generated app token as GH_TOKEN for gh pr review --approve and gh pr merge --auto --squash.
  • Keeps dependabot/fetch-metadata on the default GITHUB_TOKEN.

Validation

  • Reviewed workflow syntax and token usage.
  • No build required; workflow-only change.

Notes for Reviewers

Requires the Actions secrets DEPENDABOT_AUTOMERGE_APP_ID and DEPENDABOT_AUTOMERGE_PRIVATE_KEY to be available to this repository.

@github-actions github-actions Bot added the ci label Jul 22, 2026

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 96786842fa

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +27 to +28
app-id: ${{ secrets.DEPENDABOT_AUTOMERGE_APP_ID }}
private-key: ${{ secrets.DEPENDABOT_AUTOMERGE_PRIVATE_KEY }}

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Move app-token secrets off pull_request_target

Because this job only runs for Dependabot-authored pull_request_target events, GitHub's Dependabot secret restrictions mean secrets are not available in this workflow context. The newly added app-id/private-key are required by actions/create-github-app-token, so they resolve empty and the step fails before approval or auto-merge for every eligible Dependabot PR; use a pull_request/two-step workflow that can read Dependabot secrets, or avoid secrets under pull_request_target.

Useful? React with 👍 / 👎.

@ncipollina
ncipollina merged commit f6bf548 into main Jul 22, 2026
5 checks passed
@ncipollina
ncipollina deleted the ci/dependabot-app-token branch July 22, 2026 19:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant