From d0a5ccb10d8333fdc790ccbb7d3575c8ceda5d80 Mon Sep 17 00:00:00 2001 From: Jason Ross Date: Thu, 2 Jul 2026 12:48:23 -0500 Subject: [PATCH] ci: auto-update armed PRs; drop dead merge_group trigger Co-Authored-By: Claude Fable 5 --- .github/workflows/autoupdate.yml | 39 ++++++++++++++++++++++++++++++++ .github/workflows/ci.yml | 4 ---- 2 files changed, 39 insertions(+), 4 deletions(-) create mode 100644 .github/workflows/autoupdate.yml diff --git a/.github/workflows/autoupdate.yml b/.github/workflows/autoupdate.yml new file mode 100644 index 0000000..855f3ee --- /dev/null +++ b/.github/workflows/autoupdate.yml @@ -0,0 +1,39 @@ +# SPDX-License-Identifier: GPL-3.0-or-later +name: Auto-update PR branches + +# When main advances, rebase any auto-merge-armed PR that has fallen behind, so the +# "require branches up to date" branch rule doesn't need manual branch updates. Only PRs +# with GitHub auto-merge enabled are touched (PR_FILTER: auto_merge) — held/draft PRs are +# left alone. +# +# IMPORTANT: for the branch update to RE-TRIGGER the PR's CI (so it can pass and merge), +# this must run with a PAT, not the default GITHUB_TOKEN — pushes made by GITHUB_TOKEN do +# not start new workflow runs (GitHub's anti-recursion rule), so the updated PR would sit +# with stale checks. Create a fine-grained PAT scoped to this repo with +# contents:read/write + pull-requests:read/write and add it as the AUTOUPDATE_TOKEN secret. +# Without it this falls back to GITHUB_TOKEN, which updates the branch but will NOT re-run +# the PR's checks. + +on: + push: + branches: [main] + +permissions: + contents: write + pull-requests: write + +concurrency: + group: autoupdate-${{ github.ref }} + cancel-in-progress: true + +jobs: + autoupdate: + name: Auto-update armed PRs + runs-on: ubuntu-latest + steps: + - name: Update behind PRs that have auto-merge enabled + uses: chinthakagodawita/autoupdate@0707656cd062a3b0cf8fa9b2cda1d1404d74437e # v1.7.0 + env: + GITHUB_TOKEN: ${{ secrets.AUTOUPDATE_TOKEN || secrets.GITHUB_TOKEN }} + PR_FILTER: "auto_merge" + MERGE_CONFLICT_ACTION: "ignore" diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 753e50f..825d7e1 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -4,10 +4,6 @@ name: CI on: pull_request: branches: [main] - # Run the same jobs when a PR is queued in the GitHub merge queue, so the "CI passed" - # gate reports on the up-to-date merge-group ref and the queue can merge in order. - merge_group: - branches: [main] # A new push to a PR cancels any in-flight run for that PR. concurrency: