From 15c6335a6ac6d8c86b8ade65f5c5e529d9f39503 Mon Sep 17 00:00:00 2001 From: bcastets-robotiq Date: Mon, 21 Sep 2026 17:12:38 -0400 Subject: [PATCH] fix: drop the PAT and auto-merge, open the PR and stop there No credential can make this workflow both author and approve its own PR without either a second bot identity (PAT) or a ruleset bypass that would exempt every GITHUB_TOKEN-authored PR in this repo from review, not just this one. Neither is worth it just to skip one daily click: GITHUB_TOKEN alone is enough to generate the content and open the PR: a human merges once the required test check passes. Co-Authored-By: Claude Sonnet 5 --- .github/workflows/update-readme.yml | 82 ++++++++--------------------- 1 file changed, 21 insertions(+), 61 deletions(-) diff --git a/.github/workflows/update-readme.yml b/.github/workflows/update-readme.yml index f24bb99..32eb8ca 100644 --- a/.github/workflows/update-readme.yml +++ b/.github/workflows/update-readme.yml @@ -4,34 +4,20 @@ name: Update README # scripts/update-readme.mjs): the repository table (from the GitHub API) and # the software tools tables (imported from robotiq/robotiq.github.io's # docs/intro.mdx). Opens a PR only when the regenerated content actually -# differs, then auto-merges it — mirroring -# robotiq.github.io's .github/workflows/dependabot-auto-merge.yml. +# differs — a human merges it. # -# Why this needs a PAT instead of just GITHUB_TOKEN: the prToMain ruleset's -# required-review rule blocks a PR's *author* from approving its own PR. In -# dependabot-auto-merge.yml, Dependabot (a distinct actor) opens the PR and -# GITHUB_TOKEN (github-actions[bot]) approves it — two different actors, so -# it's not self-approval. Here there's no Dependabot; this workflow itself -# generates the content. So the "open PR" step authenticates as -# README_BOT_PAT (a fine-grained PAT scoped to just this repo, Contents + -# Pull requests: write) instead of GITHUB_TOKEN, making its author a -# distinct actor from the github-actions[bot] identity that then approves -# and merges it in the next step. -# -# Why this is safe to merge without further human review: the generated -# content is either the GitHub API's own repo descriptions or -# robotiq.github.io's own published docs/intro.mdx — both already public and -# already reviewed upstream. What actually gates the merge is the "Test" -# workflow (.github/workflows/test.yml) as a required status check on the -# prToMain ruleset: `gh pr merge --auto` waits on it, so a change that breaks -# update-readme.mjs sits as an open, failing PR instead of reaching the org's -# public landing page. Without that required check, `--auto` has nothing to -# wait on and errors out instead of merging — see the review on PR #2. -# -# Also requires: `allow_auto_merge` enabled on this repo (Settings → General -# → Pull Requests), and the commit's author email resolving to a real GitHub -# account (below) so prToMain's require_extra_approval_for_unattributed_changes -# rule doesn't kick in and demand a second approval nothing here can produce. +# Why this doesn't auto-merge: the prToMain ruleset requires 1 approving +# review, and blocks a PR's *author* from approving its own PR. GITHUB_TOKEN +# always acts as github-actions[bot], and this workflow both generates the +# content and would be the one opening the PR — so the author and the only +# available approver would be the same identity. Getting a truly separate +# identity to approve needs either a PAT for a second bot/human account, or +# a ruleset bypass actor for GitHub Actions (which would exempt every +# GITHUB_TOKEN-authored PR in this repo from review, not just this one) — +# both trade one problem for another. Stopping at "PR opens automatically, +# a human clicks merge" needs neither: GITHUB_TOKEN is enough to open the +# PR, and the required `test` check (.github/workflows/test.yml) still +# gates it before that merge is possible. on: schedule: @@ -46,10 +32,7 @@ jobs: update-readme: runs-on: ubuntu-latest steps: - - name: Checkout - uses: actions/checkout@v4 - with: - token: ${{ secrets.README_BOT_PAT }} + - uses: actions/checkout@v4 - uses: actions/setup-node@v4 with: @@ -61,51 +44,28 @@ jobs: run: node scripts/update-readme.mjs - name: Open PR if content changed - id: pr env: - GH_TOKEN: ${{ secrets.README_BOT_PAT }} + GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} run: | if git diff --quiet -- profile/README.md; then - echo "changed=false" >> "$GITHUB_OUTPUT" exit 0 fi # Fixed name rather than one timestamped per run: a run that lands - # before yesterday's PR merged (still waiting on the required - # check) force-pushes onto the same branch/PR instead of piling up - # a new branch and a new unmergeable PR each day. + # before yesterday's PR merged force-pushes onto the same + # branch/PR instead of piling up a new branch and PR each day. BRANCH="auto/update-readme" - git config user.name "robotiq-readme-bot" - # This must resolve to a real GitHub account (github-actions[bot]'s - # own noreply address) or the prToMain ruleset's - # require_extra_approval_for_unattributed_changes rule treats the - # commit as unattributed and demands a second approval this - # workflow has no way to produce. + git config user.name "github-actions[bot]" git config user.email "41898282+github-actions[bot]@users.noreply.github.com" git checkout -b "$BRANCH" git add profile/README.md git commit -m "chore: update README repository table and software tools section" git push --force origin "$BRANCH" - EXISTING_PR=$(gh pr list --base main --head "$BRANCH" --state open --json url --jq '.[0].url') - if [ -n "$EXISTING_PR" ]; then - PR_URL="$EXISTING_PR" - else - PR_URL=$(gh pr create \ + if [ -z "$(gh pr list --base main --head "$BRANCH" --state open --json url --jq '.[0].url')" ]; then + gh pr create \ --base main \ --head "$BRANCH" \ --title "chore: update README repository table" \ - --body "Automated daily refresh of the repository table (GitHub API) and software tools section (robotiq.github.io docs/intro.mdx) — see \`scripts/update-readme.mjs\`.") + --body "Automated daily refresh of the repository table (GitHub API) and software tools section (robotiq.github.io docs/intro.mdx) — see \`scripts/update-readme.mjs\`. Merge once the \`test\` check passes." fi - - echo "changed=true" >> "$GITHUB_OUTPUT" - echo "url=$PR_URL" >> "$GITHUB_OUTPUT" - - - name: Approve and auto-merge - if: steps.pr.outputs.changed == 'true' - env: - GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} - PR_URL: ${{ steps.pr.outputs.url }} - run: | - gh pr review --approve "$PR_URL" - gh pr merge --auto --squash --delete-branch "$PR_URL"