ci(github): use app token for dependabot merges#23
Conversation
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: c832426140
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 879f700119
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| app-id: ${{ secrets.DEPENDABOT_AUTOMERGE_APP_ID }} | ||
| private-key: ${{ secrets.DEPENDABOT_AUTOMERGE_PRIVATE_KEY }} |
There was a problem hiding this comment.
Use a trigger that can read the app credentials
Because this job only runs for Dependabot PRs under pull_request_target, GitHub's current Dependabot secret rules say those runs do not receive workflow secrets, so these required app-id/private-key inputs will be empty and actions/create-github-app-token fails before the approve/auto-merge steps. Move the app-token work to a Dependabot-supported trigger such as pull_request with Dependabot secrets, or a follow-up workflow_run that has Actions-secret access. See GitHub's secret-type docs: https://docs.github.com/en/code-security/reference/secret-security/secret-types#dependabot-secrets
Useful? React with 👍 / 👎.
Summary
Updates the Dependabot auto-merge workflow to use the LayeredCraft GitHub App token for approving and enabling auto-merge. This avoids using
GITHUB_TOKENfor the merge operation so downstream workflows can run after Dependabot auto-merged changes land onmain.Changes
actions/create-github-app-token@v2to mint an installation token for patch/minor Dependabot PRs.GH_TOKENforgh pr review --approveandgh pr merge --auto --squash.dependabot/fetch-metadataon the defaultGITHUB_TOKEN.Validation
Notes for Reviewers
Requires the Actions secrets
DEPENDABOT_AUTOMERGE_APP_IDandDEPENDABOT_AUTOMERGE_PRIVATE_KEYto be available to this repository.