Skip to content

ci(github): use app token for dependabot merges#285

Merged
ncipollina merged 5 commits into
mainfrom
ci/dependabot-app-token
Jul 23, 2026
Merged

ci(github): use app token for dependabot merges#285
ncipollina merged 5 commits into
mainfrom
ci/dependabot-app-token

Conversation

@ncipollina

Copy link
Copy Markdown
Contributor

Summary

Updates the Dependabot auto-merge workflow to use the LayeredCraft GitHub App token for approving and enabling auto-merge. This avoids using GITHUB_TOKEN for the merge operation so downstream workflows can run after Dependabot auto-merged changes land on main.

Changes

  • Adds a SHA-pinned actions/create-github-app-token step for semver patch/minor Dependabot PRs.
  • Uses the generated app token as GH_TOKEN for gh pr review --approve and gh pr merge --auto --squash.
  • Keeps dependabot/fetch-metadata on the default GITHUB_TOKEN.

Validation

  • Reviewed workflow syntax and token usage.
  • No build required; workflow-only change.

Notes for Reviewers

Requires the Actions secrets DEPENDABOT_AUTOMERGE_APP_ID and DEPENDABOT_AUTOMERGE_PRIVATE_KEY to be available to this repository.

@github-actions github-actions Bot added the type: ci CI/CD changes label Jul 22, 2026

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 0fb35d9781

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +27 to +28
app-id: ${{ secrets.DEPENDABOT_AUTOMERGE_APP_ID }}
private-key: ${{ secrets.DEPENDABOT_AUTOMERGE_PRIVATE_KEY }}

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Avoid secrets in Dependabot pull_request_target runs

Because this job is restricted to dependabot[bot] pull_request_target events, these newly referenced app credentials are not available in the run; GitHub's secret-type docs state that Dependabot-initiated pull_request_target workflows receive a read-only GITHUB_TOKEN and no secrets (https://docs.github.com/en/code-security/reference/secret-security/secret-types#dependabot-secrets). As a result, actions/create-github-app-token will receive empty app credentials and fail before the approval/auto-merge steps for every eligible Dependabot patch/minor PR. Use a hand-off workflow under a non-Dependabot actor or another supported credential path.

Useful? React with 👍 / 👎.

@j-d-ha j-d-ha left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@ncipollina
ncipollina merged commit 92e1329 into main Jul 23, 2026
7 checks passed
@ncipollina
ncipollina deleted the ci/dependabot-app-token branch July 23, 2026 11:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

type: ci CI/CD changes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants