Files
LibreMail-Bug-Report-Ingest/.github/workflows/autoupdate.yml
T
JMR-devandClaude Opus 4.8 4c2d0ad43f autoupdate: use STATUS_CHECKS_RETRIGGER_TOKEN so branch updates re-trigger checks
The autoupdate workflow authenticated its branch-update pushes with the
default GITHUB_TOKEN. Pushes made with GITHUB_TOKEN do not re-trigger
downstream workflow runs, so status checks were not re-run on updated PR
branches.

Source the token from the STATUS_CHECKS_RETRIGGER_TOKEN PAT (scoped to the
"production" environment) instead. The action still reads GITHUB_TOKEN from
env, so only the value changes. Add `environment: production` to the job so
the environment-scoped secret is accessible, and update the explanatory
comment accordingly.

Closes #23

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-02 13:30:53 -05:00

41 lines
1.6 KiB
YAML

# Automatically keep open PR branches up to date with main.
#
# Whenever a commit lands on main (typically when a PR merges), the
# chinthakagodawita/autoupdate action merges the latest main into every open PR
# that targets main, so PR branches don't drift out of date.
#
# The update push is authenticated with a PAT (STATUS_CHECKS_RETRIGGER_TOKEN,
# sourced from the "production" GitHub Actions environment) instead of the default
# GITHUB_TOKEN. Pushes made with GITHUB_TOKEN do NOT re-trigger downstream workflow
# runs, whereas a PAT does -- so autoupdate's branch-update pushes DO re-trigger
# status checks on the updated PR branch automatically.
name: Autoupdate PR branches
on:
push:
branches: [main]
# Minimal permissions needed to update open PR branches.
permissions:
contents: write
pull-requests: write
jobs:
autoupdate:
runs-on: ubuntu-latest
# Required to read the STATUS_CHECKS_RETRIGGER_TOKEN secret, which is scoped
# to the "production" environment.
environment: production
steps:
# Pinned to a specific commit SHA (supply-chain safety); comment tracks the
# human-readable release it corresponds to.
- name: Autoupdate open PRs
uses: chinthakagodawita/autoupdate@0707656cd062a3b0cf8fa9b2cda1d1404d74437e # v1.7.0
env:
# The action reads its token from the GITHUB_TOKEN env var; we feed it
# the PAT so its pushes re-trigger downstream status checks.
GITHUB_TOKEN: ${{ secrets.STATUS_CHECKS_RETRIGGER_TOKEN }}
# Update all open PRs targeting the pushed branch.
PR_FILTER: "all"