@@ -25,17 +25,29 @@ run = "act push --job native --matrix platform:linux-aarch64"
2525# (authenticated with admin on this repository) and the 1Password CLI (`op signin` first).
2626
2727[tasks ."gh:secrets" ]
28- description = " Set the repository's Actions secrets from 1Password (op)"
28+ description = " Set the repository's Actions and Dependabot secrets from 1Password (op)"
2929shell = " bash -c"
3030quiet = true # suppress mise's `[task] $ <first line>` command echo
3131env = { NO_COLOR = " 1" } # suppress gh's OSC-11 terminal-background probe
32- run = '''
32+ run = """
3333set -euo pipefail
3434
35- # BOT_PAT is consumed by .github/workflows/update-pr-branch.yml, and it cannot be GITHUB_TOKEN:
36- # a push made with GITHUB_TOKEN does not start workflow runs, so a PR branch would be brought
37- # up to date and then never re-checked — which is the whole point of that workflow. A
38- # fine-grained PAT scoped to this repository with Contents: read and write is enough.
35+ # BOT_PAT is consumed by update-pr-branch.yml and by the auto-merge step of
36+ # dependabot-automerge.yml, and it cannot be GITHUB_TOKEN: a push made with GITHUB_TOKEN starts no
37+ # workflow runs, so a branch would be brought up to date — or a pull request merged — and then
38+ # never re-checked.
39+ #
40+ # The token needs these repository permissions:
41+ # Pull requests Write PUT /repos/{owner}/{repo}/pulls/{n}/update-branch requires it
42+ # Contents Write pushing the updated branch and the merge commit
43+ #
44+ # It is written to BOTH secret stores. A run triggered by a Dependabot event cannot read Actions
45+ # secrets at all — it reads the Dependabot store instead — so a token present only in Actions
46+ # expands to an empty string there, and gh fails with "set the GH_TOKEN environment variable".
47+ #
48+ # --repo, because this checkout has two remotes (origin and upstream) and gh refuses to guess.
49+ repo="$(git remote get-url origin | sed -E 's#(git@github\\ .com:|https://github\\ .com/)##; s#\\ .git$##')"
50+
3951apply() {
4052 local name="$1" ref="$2" value
4153 if [[ "$ref" == *TODO* ]]; then
@@ -46,9 +58,11 @@ apply() {
4658 echo " Create that item in 1Password (or point the reference at an existing one), then re-run." >&2
4759 return 1
4860 fi
49- gh secret set "$name" --body "$value"
50- echo "✓ $name set"
61+ for store in actions dependabot; do
62+ gh secret set "$name" --app "$store" --repo "$repo" --body "$value"
63+ echo "✓ $name set ($store)"
64+ done
5165}
5266
5367apply BOT_PAT 'op://Private/open-java-format/GitHub/bot-pat'
54- '''
68+ """
0 commit comments