ci(github): use app token for dependabot merges#35
Conversation
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: a1a6e39934
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| app-id: ${{ secrets.DEPENDABOT_AUTOMERGE_APP_ID }} | ||
| private-key: ${{ secrets.DEPENDABOT_AUTOMERGE_PRIVATE_KEY }} |
There was a problem hiding this comment.
Move app credentials off this Dependabot trigger
For Dependabot PRs this job always runs under pull_request_target with github.event.pull_request.user.login == 'dependabot[bot]'; GitHub documents that in that context the workflow receives a read-only token and secrets are unavailable (see GitHub Docs: Dependabot on Actions). These secrets.* values are therefore empty for the only runs that reach this step, so actions/create-github-app-token cannot mint the token and the patch/minor auto-merge path stops before approval/merge. Use a trigger that can access the app credentials, such as a follow-up privileged workflow, or another supported credential source for Dependabot runs.
Useful? React with 👍 / 👎.
Summary
Updates the Dependabot auto-merge workflow to use the repository GitHub App token for approval and auto-merge actions instead of
GITHUB_TOKEN. This keeps downstream workflows from being suppressed after Dependabot auto-merges.Changes
actions/create-github-app-tokenstep usingDEPENDABOT_AUTOMERGE_APP_IDandDEPENDABOT_AUTOMERGE_PRIVATE_KEY.dependabot/fetch-metadataonsecrets.GITHUB_TOKEN.gh pr review --approveandgh pr merge --auto --squash.app-tokenstep ID with bracket notation.Validation