# SPDX-License-Identifier: GPL-3.0-or-later name: Auto-update PR branches # When main advances, rebase every open PR that has fallen behind, so the "require # branches up to date" branch rule doesn't need manual branch updates. All open PRs are # touched (PR_FILTER: all) — this is no longer limited to PRs with GitHub auto-merge # enabled. # # IMPORTANT (issue #349): the branch update runs with the default GITHUB_TOKEN — ON PURPOSE. # A GITHUB_TOKEN push does NOT start new workflow runs (GitHub's anti-recursion rule), so # updating every behind PR here NO LONGER re-triggers every PR's CI. That deliberately breaks # the old merge-cascade (every merge -> autoupdate rebases all PRs with a PAT -> all re-run -> # ci.yml's cancel-in-progress kills each in-flight run -> PRs thrash and can't converge). # Branches still go up to date (satisfying "require branches up to date"); they just don't # auto-run CI on the new head SHA. Re-triggering that SHA's CI is now OWNED by the traffic- # controller scheduler (`.github/workflows/ci-trigger.yml` -> `traffic_control.py --mode # trigger`), which triggers the updated PRs deliberately, in priority order, a few at a time. # So this workflow must NOT use the PAT for the update push (that would re-introduce the # cascade). This workflow itself doesn't need AUTOUPDATE_TOKEN — but the secret is still REQUIRED # by the repo: the ci-trigger.yml scheduler dispatches CI with it (a GITHUB_TOKEN dispatch would # be held for manual approval and never run un-attended). Don't delete the secret. See # ci-trigger.yml + issue #351. on: push: branches: [main] pull_request: types: [opened, reopened, ready_for_review] branches: [main] permissions: contents: write pull-requests: write concurrency: group: autoupdate-${{ github.ref }} cancel-in-progress: true jobs: autoupdate: name: Auto-update open PRs runs-on: ubuntu-latest environment: CI_CD steps: - name: Update all behind PRs uses: chinthakagodawita/autoupdate@0707656cd062a3b0cf8fa9b2cda1d1404d74437e # v1.7.0 env: # Default GITHUB_TOKEN — NOT a PAT — so this update push does not auto-retrigger CI # (anti-recursion). See the header: re-triggering is owned by ci-trigger.yml. GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} PR_FILTER: "all" PR_READY_STATE: "all" MERGE_CONFLICT_ACTION: "ignore"