Skip to content

Commit 59f8e65

Browse files
committed
Merge dependabot PRs with BOT_PAT, not GITHUB_TOKEN
Auto-merge completes on behalf of whoever enabled it, and a push made by GITHUB_TOKEN starts no workflow runs. Enabled with GITHUB_TOKEN the merge landed on main silently: no CI, no CodeQL, no dependency snapshot, and update-pr-branch never woke to rebase the remaining PRs — the automation cut its own legs one merge at a time. The approval stays on GITHUB_TOKEN. A review triggers nothing and does not need to, so the short-lived token is enough there and the approval reads as the bot rather than as a person. That step needs can_approve_pull_request_reviews on the repository, which is now enabled; no permissions block substitutes for it.
1 parent 231581c commit 59f8e65

1 file changed

Lines changed: 11 additions & 1 deletion

File tree

‎.github/workflows/dependabot-automerge.yml‎

Lines changed: 11 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -17,16 +17,26 @@ jobs:
1717
with:
1818
github-token: "${{ secrets.GITHUB_TOKEN }}"
1919

20+
# GITHUB_TOKEN, deliberately: a review starts no workflow run and does not need to, so the
21+
# short-lived token is enough and the approval shows in the PR as the bot rather than as a
22+
# person. This needs `can_approve_pull_request_reviews` on the repository — no `permissions`
23+
# block can stand in for it, and without it GitHub refuses with "GitHub Actions is not
24+
# permitted to approve pull requests".
2025
- name: Approve patch and minor updates
2126
if: steps.metadata.outputs.update-type != 'version-update:semver-major'
2227
run: gh pr review --approve "$PR_URL"
2328
env:
2429
PR_URL: ${{ github.event.pull_request.html_url }}
2530
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
2631

32+
# BOT_PAT here, and not GITHUB_TOKEN: auto-merge is completed on behalf of whoever enabled
33+
# it, and a push made by GITHUB_TOKEN starts no workflow runs. Enabled with GITHUB_TOKEN the
34+
# merge lands on main silently — no CI, no CodeQL, no dependency snapshot, and
35+
# update-pr-branch never wakes to rebase the remaining PRs, so the automation cuts its own
36+
# legs. A PAT is a real user, so the push behaves like any other.
2737
- name: Enable auto-merge for patch and minor updates
2838
if: steps.metadata.outputs.update-type != 'version-update:semver-major'
2939
run: gh pr merge --auto --squash "$PR_URL"
3040
env:
3141
PR_URL: ${{ github.event.pull_request.html_url }}
32-
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
42+
GH_TOKEN: ${{ secrets.BOT_PAT }}

0 commit comments

Comments
 (0)