From db157bdb98d600504372cb5b01a52fdf09ab5ba0 Mon Sep 17 00:00:00 2001 From: Marco Walz Date: Fri, 25 Sep 2026 15:48:39 +0200 Subject: [PATCH] fix(generate-changelog): push the changelog branch with the app token create-pr pushes with the credentials of the checkout, which used the default token. With reuse_branch, those force pushes update an open pull request as github-actions[bot]: pull_request_target workflows don't run, so required workflows never report, and pull_request workflows wait for approval where external contributors need it. --- .github/workflows/generate-changelog.yaml | 5 +++++ actions/create-pr/README.md | 4 ++++ 2 files changed, 9 insertions(+) diff --git a/.github/workflows/generate-changelog.yaml b/.github/workflows/generate-changelog.yaml index 06d0d4c..5e3b9f5 100644 --- a/.github/workflows/generate-changelog.yaml +++ b/.github/workflows/generate-changelog.yaml @@ -113,6 +113,11 @@ jobs: with: fetch-depth: 0 fetch-tags: true + # create-pr pushes with these credentials. With the default token, the + # force pushes of reuse_branch trigger no pull_request_target workflows, + # and pull_request workflows wait for approval where external + # contributors need it. + token: ${{ steps.generate_token.outputs.token }} - name: Check for release commit id: release_commit diff --git a/actions/create-pr/README.md b/actions/create-pr/README.md index ef55c36..6133692 100644 --- a/actions/create-pr/README.md +++ b/actions/create-pr/README.md @@ -4,6 +4,8 @@ This action creates a pull request from a branch to a target branch. Any pull requests created as a result of actions that use the default token (`${{ github.token }}`) will not trigger any pipeline events. To ensure that any pipelines are triggered, a different token must be used. +The branch is pushed with the git credentials of the checkout, so pass the same token to `actions/checkout`. This matters with `reuse_branch`: its force pushes update an open pull request, and when they come from the default token they trigger no `pull_request_target` workflows, and `pull_request` workflows wait for approval in repositories that require it for external contributors. + Any files that will be changed and committed to the pull request must be listed in the `.github/repo_policies/BOT_APPROVED_FILES` file of the repository. For example: ``` @@ -55,6 +57,8 @@ jobs: - name: Checkout repository uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + with: + token: ${{ steps.generate_token.outputs.token }} - name: Create pull request uses: dfinity/ci-tools/actions/create-pr@main