# SPDX-License-Identifier: GPL-3.0-or-later name: Auto-update PR branches # When main advances, rebase every open PR that has fallen behind, so the "require # branches up to date" branch rule doesn't need manual branch updates. All open PRs are # touched (PR_FILTER: all) — this is no longer limited to PRs with GitHub auto-merge # enabled. # # IMPORTANT: for the branch update to RE-TRIGGER the PR's CI (so it can pass and merge), # this must run with a PAT, not the default GITHUB_TOKEN — pushes made by GITHUB_TOKEN do # not start new workflow runs (GitHub's anti-recursion rule), so the updated PR would sit # with stale checks. Create a fine-grained PAT scoped to this repo with # contents:read/write + pull-requests:read/write and add it as the AUTOUPDATE_TOKEN secret. # Without it this falls back to GITHUB_TOKEN, which updates the branch but will NOT re-run # the PR's checks. on: push: branches: [main] pull_request: types: [opened, reopened, ready_for_review] branches: [main] permissions: contents: write pull-requests: write concurrency: group: autoupdate-${{ github.ref }} cancel-in-progress: true jobs: autoupdate: name: Auto-update open PRs runs-on: ubuntu-latest environment: CI_CD steps: - name: Update all behind PRs uses: chinthakagodawita/autoupdate@0707656cd062a3b0cf8fa9b2cda1d1404d74437e # v1.7.0 env: GITHUB_TOKEN: ${{ secrets.AUTOUPDATE_TOKEN || secrets.GITHUB_TOKEN }} PR_FILTER: "all" PR_READY_STATE: "all" MERGE_CONFLICT_ACTION: "ignore"