Skip to content

ci: open the dependency bump with a token whose pull requests run CI - #176

Merged
fxrdhan merged 1 commit into
devfrom
claude/deps-bump-token
Oct 6, 2026
Merged

fxrdhan merged 1 commit into
devfrom
claude/deps-bump-token

Conversation

@fxrdhan

@fxrdhan fxrdhan commented Oct 6, 2026

Copy link
Copy Markdown
Owner

Summary

The weekly Automated Dependency Bump opens its pull request with GITHUB_TOKEN. Since GitHub's June 2026 change, every workflow run on such a pull request waits until someone with write access approves it, and no repository setting turns that off (docs).

That's what blocked #164:

  • Its own CI, Fuzz Canary and Dependency Advisories runs sat at action_required.
  • The CI run this workflow dispatched (gh workflow run ci.yml) passed on the same commit. But GitHub doesn't tie a workflow_dispatch run's checks to a pull request, so the dev ruleset never saw its CI result, and the pull request stayed BLOCKED.
  • It merged only after its runs were approved by hand.

The fix:

  • When the DEPENDENCY_BUMP_TOKEN secret is set, the workflow uses it to push the branch and open the pull request. The pull request's pull_request runs then start on their own and report CI result. GitHub's docs name a personal access token or a GitHub App token as the way to skip the approval.
  • Without the secret, it falls back to GITHUB_TOKEN, as before. The runs wait for Approve workflows to run in the merge box.
  • The ci.yml dispatch goes, along with the actions: write permission it needed. It satisfied the merge gate in neither case, and ran CI a second time.

To finish the setup (maintainer)

  1. Create a fine-grained personal access token:
    • Repository access: only fxrdhan/lez
    • Permissions: Contents (read and write) and Pull requests (read and write). Metadata (read) is added automatically.
    • The bump only touches Cargo.lock and flake.lock, so it doesn't need the Workflows permission.
  2. Store it as a secret on your own machine, so the token never passes through a chat:
    gh secret set DEPENDENCY_BUMP_TOKEN --repo fxrdhan/lez
  3. Pull requests the bump opens will then be authored by your account. When the token expires, the push fails, which shows in the bump run.

Type of Change

  • 🐛 Bug fix (non-breaking change fixing an issue)
  • ✨ New feature (non-breaking change adding functionality)
  • ⚡ Performance improvement
  • ♻️ Code refactor / clean-up
  • 💥 Breaking change (fix or feature that would cause existing functionality to change)
  • 📝 Documentation / Man pages / Completions
  • 🔧 Build / CI / Dependencies

Related Issues & Upstream References

How Has This Been Tested?

  • Testing commands executed: nix fmt (no changes) and actionlint on the workflow.
  • Platforms verified:
    • The token path can't run until the secret exists. Even then, a manual run only opens a pull request when there are updates, and build(deps): Automatic dependency updates for 2026-10-06 #164 took this week's.
    • The first real test is Thursday's scheduled run, or a manual run after a dependency has released.
    • Without the secret, the workflow keeps today's behavior, minus the dispatch.

Contributor Checklist

  • Base branch is set to dev (unless this is a release PR targeting main)
  • My commits follow Conventional Commits format
  • Tests covering the changes have been added/updated
  • cargo clippy --all-targets passes with no warnings
  • cargo nextest run (or cargo test) passes
  • cargo fmt --check / nix fmt passes
  • License headers (SPDX / REUSE) are properly preserved/added

🤖 Generated with Claude Code

Since June 2026, GitHub holds every workflow run on a pull request that
GITHUB_TOKEN opens or updates until someone with write access approves
it, and no setting turns that off. #164 sat blocked: its own CI, Fuzz
Canary and Dependency Advisories runs waited for approval. The CI run
this workflow dispatched passed on the same commit, but GitHub does not
tie a workflow_dispatch run's checks to a pull request, so the dev
ruleset never saw its `CI result`.

Push the branch and open the pull request with DEPENDENCY_BUMP_TOKEN, a
fine-grained personal access token, when that secret is set, so CI
starts on its own and the ruleset sees it. Without the secret,
GITHUB_TOKEN carries on as before. The dispatch helped in neither case,
and goes, with the actions permission it needed.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@fxrdhan
fxrdhan merged commit 3c7c8e3 into dev Oct 6, 2026
9 checks passed
@fxrdhan
fxrdhan deleted the claude/deps-bump-token branch October 6, 2026 07:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant