Skip to content

Commit 39ece6d

Browse files
committed
Write BOT_PAT to the Dependabot secret store as well
A workflow run triggered by a Dependabot event cannot read Actions secrets; it reads the Dependabot store instead. BOT_PAT lived only in Actions, so secrets.BOT_PAT expanded to an empty string in dependabot-automerge.yml and gh refused with "set the GH_TOKEN environment variable" — while the same secret worked in update-pr-branch.yml, which runs on push and schedule. Also corrects the permissions this token needs. Contents: Write alone is not enough: PUT /repos/{owner}/{repo}/pulls/{n}/update-branch requires Pull requests: Write, which is what update-pr-branch.yml was failing on with "Resource not accessible by personal access token". --repo is passed explicitly because this checkout has both origin and upstream remotes and gh refuses to guess between them.
1 parent 217a6c1 commit 39ece6d

1 file changed

Lines changed: 23 additions & 9 deletions

File tree

‎mise.toml‎

Lines changed: 23 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -25,17 +25,29 @@ run = "act push --job native --matrix platform:linux-aarch64"
2525
# (authenticated with admin on this repository) and the 1Password CLI (`op signin` first).
2626

2727
[tasks."gh:secrets"]
28-
description = "Set the repository's Actions secrets from 1Password (op)"
28+
description = "Set the repository's Actions and Dependabot secrets from 1Password (op)"
2929
shell = "bash -c"
3030
quiet = true # suppress mise's `[task] $ <first line>` command echo
3131
env = { NO_COLOR = "1" } # suppress gh's OSC-11 terminal-background probe
32-
run = '''
32+
run = """
3333
set -euo pipefail
3434
35-
# BOT_PAT is consumed by .github/workflows/update-pr-branch.yml, and it cannot be GITHUB_TOKEN:
36-
# a push made with GITHUB_TOKEN does not start workflow runs, so a PR branch would be brought
37-
# up to date and then never re-checked — which is the whole point of that workflow. A
38-
# fine-grained PAT scoped to this repository with Contents: read and write is enough.
35+
# BOT_PAT is consumed by update-pr-branch.yml and by the auto-merge step of
36+
# dependabot-automerge.yml, and it cannot be GITHUB_TOKEN: a push made with GITHUB_TOKEN starts no
37+
# workflow runs, so a branch would be brought up to date — or a pull request merged — and then
38+
# never re-checked.
39+
#
40+
# The token needs these repository permissions:
41+
# Pull requests Write PUT /repos/{owner}/{repo}/pulls/{n}/update-branch requires it
42+
# Contents Write pushing the updated branch and the merge commit
43+
#
44+
# It is written to BOTH secret stores. A run triggered by a Dependabot event cannot read Actions
45+
# secrets at all — it reads the Dependabot store instead — so a token present only in Actions
46+
# expands to an empty string there, and gh fails with "set the GH_TOKEN environment variable".
47+
#
48+
# --repo, because this checkout has two remotes (origin and upstream) and gh refuses to guess.
49+
repo="$(git remote get-url origin | sed -E 's#(git@github\\.com:|https://github\\.com/)##; s#\\.git$##')"
50+
3951
apply() {
4052
local name="$1" ref="$2" value
4153
if [[ "$ref" == *TODO* ]]; then
@@ -46,9 +58,11 @@ apply() {
4658
echo " Create that item in 1Password (or point the reference at an existing one), then re-run." >&2
4759
return 1
4860
fi
49-
gh secret set "$name" --body "$value"
50-
echo "✓ $name set"
61+
for store in actions dependabot; do
62+
gh secret set "$name" --app "$store" --repo "$repo" --body "$value"
63+
echo "✓ $name set ($store)"
64+
done
5165
}
5266
5367
apply BOT_PAT 'op://Private/open-java-format/GitHub/bot-pat'
54-
'''
68+
"""

0 commit comments

Comments
 (0)