Skip to content

ci(github): use app token for dependabot merges#65

Merged
ncipollina merged 2 commits into
mainfrom
ci/dependabot-app-token
Jul 22, 2026
Merged

ci(github): use app token for dependabot merges#65
ncipollina merged 2 commits into
mainfrom
ci/dependabot-app-token

Conversation

@ncipollina

Copy link
Copy Markdown
Collaborator

Summary

Updates the Dependabot auto-merge workflow to use the LayeredCraft GitHub App token for approving and enabling auto-merge. This avoids using GITHUB_TOKEN for the merge operation so downstream workflows can run after Dependabot auto-merged changes land on main.

Changes

  • Adds a SHA-pinned actions/create-github-app-token step for semver patch/minor Dependabot PRs.
  • Uses the generated app token as GH_TOKEN for gh pr review --approve and gh pr merge --auto --squash.
  • Keeps dependabot/fetch-metadata on the default GITHUB_TOKEN.

Validation

  • Reviewed workflow syntax and token usage.
  • No build required; workflow-only change.

Notes for Reviewers

Requires the Actions secrets DEPENDABOT_AUTOMERGE_APP_ID and DEPENDABOT_AUTOMERGE_PRIVATE_KEY to be available to this repository.

@github-actions github-actions Bot added the ci label Jul 22, 2026

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 7e594409b0

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +27 to +28
app-id: ${{ secrets.DEPENDABOT_AUTOMERGE_APP_ID }}
private-key: ${{ secrets.DEPENDABOT_AUTOMERGE_PRIVATE_KEY }}

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Use a trigger that can read the app credentials

In this pull_request_target job, the only runs that reach this step are Dependabot-authored PRs (github.event.pull_request.user.login == 'dependabot[bot]'). GitHub documents that Dependabot-initiated pull_request_target runs with that condition get a read-only GITHUB_TOKEN and no secrets, so these new app-id/private-key inputs evaluate empty and actions/create-github-app-token fails before the approve/auto-merge steps can use the app token. Move the token generation to a Dependabot context that exposes the credentials, such as a pull_request workflow using Dependabot secrets, or another trusted two-step workflow.

Useful? React with 👍 / 👎.

@ncipollina
ncipollina merged commit 4728cf6 into main Jul 22, 2026
5 checks passed
@ncipollina
ncipollina deleted the ci/dependabot-app-token branch July 22, 2026 19:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant