The autoupdate workflow authenticated its branch-update pushes with the default GITHUB_TOKEN. Pushes made with GITHUB_TOKEN do not re-trigger downstream workflow runs, so status checks were not re-run on updated PR branches. Source the token from the STATUS_CHECKS_RETRIGGER_TOKEN PAT (scoped to the "production" environment) instead. The action still reads GITHUB_TOKEN from env, so only the value changes. Add `environment: production` to the job so the environment-scoped secret is accessible, and update the explanatory comment accordingly. Closes #23 Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
41 lines
1.6 KiB
YAML
41 lines
1.6 KiB
YAML
# Automatically keep open PR branches up to date with main.
|
|
#
|
|
# Whenever a commit lands on main (typically when a PR merges), the
|
|
# chinthakagodawita/autoupdate action merges the latest main into every open PR
|
|
# that targets main, so PR branches don't drift out of date.
|
|
#
|
|
# The update push is authenticated with a PAT (STATUS_CHECKS_RETRIGGER_TOKEN,
|
|
# sourced from the "production" GitHub Actions environment) instead of the default
|
|
# GITHUB_TOKEN. Pushes made with GITHUB_TOKEN do NOT re-trigger downstream workflow
|
|
# runs, whereas a PAT does -- so autoupdate's branch-update pushes DO re-trigger
|
|
# status checks on the updated PR branch automatically.
|
|
|
|
name: Autoupdate PR branches
|
|
|
|
on:
|
|
push:
|
|
branches: [main]
|
|
|
|
# Minimal permissions needed to update open PR branches.
|
|
permissions:
|
|
contents: write
|
|
pull-requests: write
|
|
|
|
jobs:
|
|
autoupdate:
|
|
runs-on: ubuntu-latest
|
|
# Required to read the STATUS_CHECKS_RETRIGGER_TOKEN secret, which is scoped
|
|
# to the "production" environment.
|
|
environment: production
|
|
steps:
|
|
# Pinned to a specific commit SHA (supply-chain safety); comment tracks the
|
|
# human-readable release it corresponds to.
|
|
- name: Autoupdate open PRs
|
|
uses: chinthakagodawita/autoupdate@0707656cd062a3b0cf8fa9b2cda1d1404d74437e # v1.7.0
|
|
env:
|
|
# The action reads its token from the GITHUB_TOKEN env var; we feed it
|
|
# the PAT so its pushes re-trigger downstream status checks.
|
|
GITHUB_TOKEN: ${{ secrets.STATUS_CHECKS_RETRIGGER_TOKEN }}
|
|
# Update all open PRs targeting the pushed branch.
|
|
PR_FILTER: "all"
|