feat: fully automatic daily README update via a GitHub App - #4
Merged
Merged
Conversation
Replaces the PAT-based approve/merge with a direct merge, relying on a bypass actor for the GitHub Actions app on prToMain (exempting it from the 1-review requirement) plus a separate requireTests ruleset with no bypass actors, so the test check still gates the merge. Requires two settings changes before this actually merges on its own (see PR description) — until then it'll open PRs that wait for manual merge, same as before. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
test.yml can't gate the daily PR: GitHub doesn't trigger workflow runs from events created by GITHUB_TOKEN, so the required check would never report and --auto would never fire. Run the same tests as a step before the PR is opened, and drop the planned requireTests ruleset. Also fixes EXISTING_PR picking up the literal string "null", which would have skipped gh pr create on the first run. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…les are satisfied Replaces the ruleset-bypass approach, which can't work: "GitHub Actions" isn't available as a bypass actor on this org, and a PR opened with GITHUB_TOKEN never triggers test.yml, so its required check would never report. Instead the robotiq-readme-bot App opens the PR (a distinct actor, tied to no personal account) and readme-auto-merge.yml approves it with GITHUB_TOKEN and enables auto-merge — the same two-actor arrangement that merges Dependabot's PRs on robotiq.github.io. prToMain needs no changes at all; every rule stays enforced against every actor. Also adds a concurrency group and commits under the App's bot identity so changes are attributed. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
mbegin-robotiq
approved these changes
Sep 22, 2026
mbegin-robotiq
left a comment
Contributor
There was a problem hiding this comment.
Reviewed the App-based design. Verified: the private key mints an installation token scoped to robotiq/.github only; all three workflows parse; tests pass 16/16; readme-auto-merge.yml has no checkout step; and its actor/branch gate correctly skipped on this PR. prToMain is unchanged — no bypass actors, all rules still enforced.
2 of 3 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem with the previous mechanism (PR #2)
The daily workflow originally used a fine-grained PAT (
README_BOT_PAT) to open the PR as a distinct GitHub identity fromgithub-actions[bot], so that identity could approve the PR — theprToMainruleset blocks a PR's author from approving it, but not a different actor.That PAT was never set up: it meant either tying the automation to a specific person's personal account (rotation, ownership and offboarding all become that individual's problem) or standing up a dedicated bot account for one workflow. So the workflow was never functional — a manual trigger failed at Checkout with
Input required and not supplied: token.This PR's fix
The instinct behind PR #2 was right — this genuinely needs a second actor — it just reached for the wrong kind. A GitHub App (
robotiq-readme-bot, installed on this repo only) is a second actor that belongs to the org rather than to a person, so there's nothing to rotate when someone leaves.update-readme.ymlmints an App installation token and opens the daily PR with it.GITHUB_TOKEN,test.ymlactually runs and the requiredtestcheck reports.readme-auto-merge.ymlapproves the PR withGITHUB_TOKEN(github-actions[bot]— a different actor from the App, so not self-approval) and enables auto-merge.testgoes green.This is the same two-actor arrangement that already merges Dependabot's PRs on
robotiq.github.io(dependabot-auto-merge.yml), with the App standing in for Dependabot.Settings required
None.
prToMainis unchanged — 1 required approval,testrequired,bypass_actors: []. Every rule stays enforced against every actor, including the bot.Credentials are already in place:
APP_ID(repo variable) andAPP_PRIVATE_KEY(repo secret). The key has been verified to mint an installation token scoped torobotiq/.githuband nothing else.Why the ruleset-bypass approach was abandoned
Earlier revisions of this PR tried to let
github-actions[bot]bypassprToMain, first alongside a separate no-bypassrequireTestsruleset, then with the test running in-job. Both are dead ends:GITHUB_TOKENnever triggerstest.yml. GitHub deliberately doesn't create workflow runs from events made with that token, so the required check would sit at "expected — waiting for status" forever and--autowould never fire. (A June 2026 change tightened this further.) This is what killed therequireTestssplit.Actor GitHub Actions integration must be part of the ruleset source or owner organization.The App route avoids the question entirely by satisfying the rules instead of exempting anyone from them — a better outcome than the bypass would have been, since the bypass would have exempted the bot from all four rules including the test check.
Other fixes carried in this PR
EXISTING_PRpicked up the literal string"null"from--jq '.[0].url'on an empty list, so[ -n ]always matched,gh pr createwas skipped and the merge ran againstnull. Fixed with// empty.concurrencygroup so a manualworkflow_dispatchduring the scheduled run can't produce two jobs racing on the same branch.332551394+robotiq-readme-bot[bot]@users.noreply.github.com) so they're attributed —prToMainsetsrequire_extra_approval_for_unattributed_changes, which would otherwise demand a second approval.update-readme.yml's ownGITHUB_TOKENis down tocontents: read; the App token does the writing.Test plan
node --test scripts/*.test.mjspasses (16/16)robotiq/.githubonlyreadme-auto-merge.ymlconfirmed to have no checkout step (it approves and merges with a write-capable token)update-readme.ymlviaworkflow_dispatchand confirm: App opens the PR →testruns and passes →github-actions[bot]approves → auto-merge completes, with zero manual stepstest🤖 Generated with Claude Code