ci: auto-update armed PRs; drop dead merge_group trigger #146

Merged
JMR-dev merged 1 commits from ci-autoupdate into main 2026-07-02 17:48:31 +00:00
JMR-dev commented 2026-07-02 17:48:27 +00:00 (Migrated from github.com)

Two workflow-only changes:

  1. Adds .github/workflows/autoupdate.yml (chinthakagodawita/autoupdate v1.7.0, MIT, SHA-pinned). On every push to main, it rebases any PR that has auto-merge enabled and has fallen behind — so the "require branches up to date" rule no longer needs manual branch updates. PR_FILTER: auto_merge leaves held/draft PRs (e.g. the review-gated spike) untouched.
  2. Removes the dead merge_group: trigger from ci.yml (added in #139) — merge queue isn't available for this user-owned repo, so that event never fired.

⚠️ Requires a PAT to fully work

For the branch update to re-trigger the PR's CI (so it can then merge), the workflow must run with a PAT, not the default GITHUB_TOKEN — pushes by GITHUB_TOKEN don't start new workflow runs (GitHub anti-recursion). Create a fine-grained PAT scoped to this repo with contents: read/write + pull-requests: read/write and add it as the AUTOUPDATE_TOKEN repo secret. Without it, it falls back to GITHUB_TOKEN (updates the branch but won't re-run checks).

Workflow-only change; admin-merged past the E2E matrix (nothing app-side to test).

🤖 Generated with Claude Code

Two workflow-only changes: 1. **Adds `.github/workflows/autoupdate.yml`** (`chinthakagodawita/autoupdate` v1.7.0, MIT, SHA-pinned). On every push to `main`, it rebases any PR that has **auto-merge enabled** and has fallen behind — so the "require branches up to date" rule no longer needs manual branch updates. `PR_FILTER: auto_merge` leaves held/draft PRs (e.g. the review-gated spike) untouched. 2. **Removes the dead `merge_group:` trigger** from `ci.yml` (added in #139) — merge queue isn't available for this user-owned repo, so that event never fired. ## ⚠️ Requires a PAT to fully work For the branch update to **re-trigger the PR's CI** (so it can then merge), the workflow must run with a PAT, not the default `GITHUB_TOKEN` — pushes by `GITHUB_TOKEN` don't start new workflow runs (GitHub anti-recursion). **Create a fine-grained PAT** scoped to this repo with `contents: read/write` + `pull-requests: read/write` and add it as the **`AUTOUPDATE_TOKEN`** repo secret. Without it, it falls back to `GITHUB_TOKEN` (updates the branch but won't re-run checks). Workflow-only change; admin-merged past the E2E matrix (nothing app-side to test). 🤖 Generated with [Claude Code](https://claude.com/claude-code)
Sign in to join this conversation.