Skip to content

Commit e1b707d

Browse files
authored
Merge branch 'main' into dependabot/github_actions/main/github/codeql-action/analyze-4.37.9
2 parents 96639d9 + a826102 commit e1b707d

2 files changed

Lines changed: 24 additions & 21 deletions

File tree

‎.github/workflows/dependabot-automerge.yml‎

Lines changed: 1 addition & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -17,25 +17,14 @@ jobs:
1717
with:
1818
github-token: "${{ secrets.GITHUB_TOKEN }}"
1919

20-
# GITHUB_TOKEN, deliberately: a review starts no workflow run and does not need to, so the
21-
# short-lived token is enough and the approval shows in the PR as the bot rather than as a
22-
# person. This needs `can_approve_pull_request_reviews` on the repository — no `permissions`
23-
# block can stand in for it, and without it GitHub refuses with "GitHub Actions is not
24-
# permitted to approve pull requests".
2520
- name: Approve patch and minor updates
2621
if: steps.metadata.outputs.update-type != 'version-update:semver-major'
2722
run: gh pr review --approve "$PR_URL"
2823
env:
2924
PR_URL: ${{ github.event.pull_request.html_url }}
3025
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
3126

32-
# BOT_PAT here, and not GITHUB_TOKEN: auto-merge is completed on behalf of whoever enabled
33-
# it, and a push made by GITHUB_TOKEN starts no workflow runs. Enabled with GITHUB_TOKEN the
34-
# merge lands on main silently — no CI, no CodeQL, no dependency snapshot, and
35-
# update-pr-branch never wakes to rebase the remaining PRs, so the automation cuts its own
36-
# legs. A PAT is a real user, so the push behaves like any other.
37-
- name: Enable auto-merge for patch and minor updates
38-
if: steps.metadata.outputs.update-type != 'version-update:semver-major'
27+
- name: Enable auto-merge for all PRs
3928
run: gh pr merge --auto --squash "$PR_URL"
4029
env:
4130
PR_URL: ${{ github.event.pull_request.html_url }}

‎mise.toml‎

Lines changed: 23 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -25,17 +25,29 @@ run = "act push --job native --matrix platform:linux-aarch64"
2525
# (authenticated with admin on this repository) and the 1Password CLI (`op signin` first).
2626

2727
[tasks."gh:secrets"]
28-
description = "Set the repository's Actions secrets from 1Password (op)"
28+
description = "Set the repository's Actions and Dependabot secrets from 1Password (op)"
2929
shell = "bash -c"
3030
quiet = true # suppress mise's `[task] $ <first line>` command echo
3131
env = { NO_COLOR = "1" } # suppress gh's OSC-11 terminal-background probe
32-
run = '''
32+
run = """
3333
set -euo pipefail
3434
35-
# BOT_PAT is consumed by .github/workflows/update-pr-branch.yml, and it cannot be GITHUB_TOKEN:
36-
# a push made with GITHUB_TOKEN does not start workflow runs, so a PR branch would be brought
37-
# up to date and then never re-checked — which is the whole point of that workflow. A
38-
# fine-grained PAT scoped to this repository with Contents: read and write is enough.
35+
# BOT_PAT is consumed by update-pr-branch.yml and by the auto-merge step of
36+
# dependabot-automerge.yml, and it cannot be GITHUB_TOKEN: a push made with GITHUB_TOKEN starts no
37+
# workflow runs, so a branch would be brought up to date — or a pull request merged — and then
38+
# never re-checked.
39+
#
40+
# The token needs these repository permissions:
41+
# Pull requests Write PUT /repos/{owner}/{repo}/pulls/{n}/update-branch requires it
42+
# Contents Write pushing the updated branch and the merge commit
43+
#
44+
# It is written to BOTH secret stores. A run triggered by a Dependabot event cannot read Actions
45+
# secrets at all — it reads the Dependabot store instead — so a token present only in Actions
46+
# expands to an empty string there, and gh fails with "set the GH_TOKEN environment variable".
47+
#
48+
# --repo, because this checkout has two remotes (origin and upstream) and gh refuses to guess.
49+
repo="$(git remote get-url origin | sed -E 's#(git@github\\.com:|https://github\\.com/)##; s#\\.git$##')"
50+
3951
apply() {
4052
local name="$1" ref="$2" value
4153
if [[ "$ref" == *TODO* ]]; then
@@ -46,9 +58,11 @@ apply() {
4658
echo " Create that item in 1Password (or point the reference at an existing one), then re-run." >&2
4759
return 1
4860
fi
49-
gh secret set "$name" --body "$value"
50-
echo "✓ $name set"
61+
for store in actions dependabot; do
62+
gh secret set "$name" --app "$store" --repo "$repo" --body "$value"
63+
echo "✓ $name set ($store)"
64+
done
5165
}
5266
5367
apply BOT_PAT 'op://Private/open-java-format/GitHub/bot-pat'
54-
'''
68+
"""

0 commit comments

Comments
 (0)