Commit 39ece6d
committed
Write BOT_PAT to the Dependabot secret store as well
A workflow run triggered by a Dependabot event cannot read Actions secrets;
it reads the Dependabot store instead. BOT_PAT lived only in Actions, so
secrets.BOT_PAT expanded to an empty string in dependabot-automerge.yml and
gh refused with "set the GH_TOKEN environment variable" — while the same
secret worked in update-pr-branch.yml, which runs on push and schedule.
Also corrects the permissions this token needs. Contents: Write alone is not
enough: PUT /repos/{owner}/{repo}/pulls/{n}/update-branch requires Pull
requests: Write, which is what update-pr-branch.yml was failing on with
"Resource not accessible by personal access token".
--repo is passed explicitly because this checkout has both origin and
upstream remotes and gh refuses to guess between them.1 parent 217a6c1 commit 39ece6d
1 file changed
Lines changed: 23 additions & 9 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
25 | 25 | | |
26 | 26 | | |
27 | 27 | | |
28 | | - | |
| 28 | + | |
29 | 29 | | |
30 | 30 | | |
31 | 31 | | |
32 | | - | |
| 32 | + | |
33 | 33 | | |
34 | 34 | | |
35 | | - | |
36 | | - | |
37 | | - | |
38 | | - | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
39 | 51 | | |
40 | 52 | | |
41 | 53 | | |
| |||
46 | 58 | | |
47 | 59 | | |
48 | 60 | | |
49 | | - | |
50 | | - | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
51 | 65 | | |
52 | 66 | | |
53 | 67 | | |
54 | | - | |
| 68 | + | |
0 commit comments