Repository navigation
ci: open the dependency bump with a token whose pull requests run CI - #176
Merged
Merged
Conversation
Since June 2026, GitHub holds every workflow run on a pull request that GITHUB_TOKEN opens or updates until someone with write access approves it, and no setting turns that off. #164 sat blocked: its own CI, Fuzz Canary and Dependency Advisories runs waited for approval. The CI run this workflow dispatched passed on the same commit, but GitHub does not tie a workflow_dispatch run's checks to a pull request, so the dev ruleset never saw its `CI result`. Push the branch and open the pull request with DEPENDENCY_BUMP_TOKEN, a fine-grained personal access token, when that secret is set, so CI starts on its own and the ruleset sees it. Without the secret, GITHUB_TOKEN carries on as before. The dispatch helped in neither case, and goes, with the actions permission it needed. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
The weekly Automated Dependency Bump opens its pull request with
GITHUB_TOKEN. Since GitHub's June 2026 change, every workflow run on such a pull request waits until someone with write access approves it, and no repository setting turns that off (docs).That's what blocked #164:
action_required.gh workflow run ci.yml) passed on the same commit. But GitHub doesn't tie aworkflow_dispatchrun's checks to a pull request, so thedevruleset never saw itsCI result, and the pull request stayed BLOCKED.The fix:
DEPENDENCY_BUMP_TOKENsecret is set, the workflow uses it to push the branch and open the pull request. The pull request'spull_requestruns then start on their own and reportCI result. GitHub's docs name a personal access token or a GitHub App token as the way to skip the approval.GITHUB_TOKEN, as before. The runs wait for Approve workflows to run in the merge box.ci.ymldispatch goes, along with theactions: writepermission it needed. It satisfied the merge gate in neither case, and ran CI a second time.To finish the setup (maintainer)
fxrdhan/lezCargo.lockandflake.lock, so it doesn't need the Workflows permission.gh secret set DEPENDENCY_BUMP_TOKEN --repo fxrdhan/lezType of Change
Related Issues & Upstream References
How Has This Been Tested?
nix fmt(no changes) andactionlinton the workflow.Contributor Checklist
dev(unless this is a release PR targetingmain)cargo clippy --all-targetspasses with no warningscargo nextest run(orcargo test) passescargo fmt --check/nix fmtpasses🤖 Generated with Claude Code