@@ -17,25 +17,14 @@ jobs:
1717 with :
1818 github-token : " ${{ secrets.GITHUB_TOKEN }}"
1919
20- # GITHUB_TOKEN, deliberately: a review starts no workflow run and does not need to, so the
21- # short-lived token is enough and the approval shows in the PR as the bot rather than as a
22- # person. This needs `can_approve_pull_request_reviews` on the repository — no `permissions`
23- # block can stand in for it, and without it GitHub refuses with "GitHub Actions is not
24- # permitted to approve pull requests".
2520 - name : Approve patch and minor updates
2621 if : steps.metadata.outputs.update-type != 'version-update:semver-major'
2722 run : gh pr review --approve "$PR_URL"
2823 env :
2924 PR_URL : ${{ github.event.pull_request.html_url }}
3025 GH_TOKEN : ${{ secrets.GITHUB_TOKEN }}
3126
32- # BOT_PAT here, and not GITHUB_TOKEN: auto-merge is completed on behalf of whoever enabled
33- # it, and a push made by GITHUB_TOKEN starts no workflow runs. Enabled with GITHUB_TOKEN the
34- # merge lands on main silently — no CI, no CodeQL, no dependency snapshot, and
35- # update-pr-branch never wakes to rebase the remaining PRs, so the automation cuts its own
36- # legs. A PAT is a real user, so the push behaves like any other.
37- - name : Enable auto-merge for patch and minor updates
38- if : steps.metadata.outputs.update-type != 'version-update:semver-major'
27+ - name : Enable auto-merge for all PRs
3928 run : gh pr merge --auto --squash "$PR_URL"
4029 env :
4130 PR_URL : ${{ github.event.pull_request.html_url }}
0 commit comments