Skip to content

feat: fully automatic daily README update via a GitHub App - #4

Merged
mbegin-robotiq merged 3 commits into
mainfrom
bypass-actor-no-pat
Sep 22, 2026
Merged

mbegin-robotiq merged 3 commits into
mainfrom
bypass-actor-no-pat

Conversation

@bcastets-robotiq

@bcastets-robotiq bcastets-robotiq commented Sep 21, 2026 •

Copy link
Copy Markdown
Collaborator

Problem with the previous mechanism (PR #2)

The daily workflow originally used a fine-grained PAT (README_BOT_PAT) to open the PR as a distinct GitHub identity from github-actions[bot], so that identity could approve the PR — the prToMain ruleset blocks a PR's author from approving it, but not a different actor.

That PAT was never set up: it meant either tying the automation to a specific person's personal account (rotation, ownership and offboarding all become that individual's problem) or standing up a dedicated bot account for one workflow. So the workflow was never functional — a manual trigger failed at Checkout with Input required and not supplied: token.

This PR's fix

The instinct behind PR #2 was right — this genuinely needs a second actor — it just reached for the wrong kind. A GitHub App (robotiq-readme-bot, installed on this repo only) is a second actor that belongs to the org rather than to a person, so there's nothing to rotate when someone leaves.

  1. update-readme.yml mints an App installation token and opens the daily PR with it.
  2. Because that token isn't GITHUB_TOKEN, test.yml actually runs and the required test check reports.
  3. readme-auto-merge.yml approves the PR with GITHUB_TOKEN (github-actions[bot] — a different actor from the App, so not self-approval) and enables auto-merge.
  4. Auto-merge completes once test goes green.

This is the same two-actor arrangement that already merges Dependabot's PRs on robotiq.github.io (dependabot-auto-merge.yml), with the App standing in for Dependabot.

Settings required

None. prToMain is unchanged — 1 required approval, test required, bypass_actors: []. Every rule stays enforced against every actor, including the bot.

Credentials are already in place: APP_ID (repo variable) and APP_PRIVATE_KEY (repo secret). The key has been verified to mint an installation token scoped to robotiq/.github and nothing else.

Why the ruleset-bypass approach was abandoned

Earlier revisions of this PR tried to let github-actions[bot] bypass prToMain, first alongside a separate no-bypass requireTests ruleset, then with the test running in-job. Both are dead ends:

  • A PR opened with GITHUB_TOKEN never triggers test.yml. GitHub deliberately doesn't create workflow runs from events made with that token, so the required check would sit at "expected — waiting for status" forever and --auto would never fire. (A June 2026 change tightened this further.) This is what killed the requireTests split.
  • "GitHub Actions" isn't offered as a bypass actor on this org, so the bypass couldn't be granted at all. The REST API rejects it with Actor GitHub Actions integration must be part of the ruleset source or owner organization.

The App route avoids the question entirely by satisfying the rules instead of exempting anyone from them — a better outcome than the bypass would have been, since the bypass would have exempted the bot from all four rules including the test check.

Other fixes carried in this PR

  • EXISTING_PR picked up the literal string "null" from --jq '.[0].url' on an empty list, so [ -n ] always matched, gh pr create was skipped and the merge ran against null. Fixed with // empty.
  • Added a concurrency group so a manual workflow_dispatch during the scheduled run can't produce two jobs racing on the same branch.
  • Commits are made under the App's bot identity (332551394+robotiq-readme-bot[bot]@users.noreply.github.com) so they're attributed — prToMain sets require_extra_approval_for_unattributed_changes, which would otherwise demand a second approval.
  • update-readme.yml's own GITHUB_TOKEN is down to contents: read; the App token does the writing.

Test plan

  • All three workflows parse; step lists and job conditions verified
  • node --test scripts/*.test.mjs passes (16/16)
  • App private key verified to authenticate and mint an installation token scoped to robotiq/.github only
  • readme-auto-merge.yml confirmed to have no checkout step (it approves and merges with a write-capable token)
  • Trigger update-readme.yml via workflow_dispatch and confirm: App opens the PR → test runs and passes → github-actions[bot] approves → auto-merge completes, with zero manual steps
  • Confirm a human PR still requires an approval and a passing test

🤖 Generated with Claude Code

Replaces the PAT-based approve/merge with a direct merge, relying on
a bypass actor for the GitHub Actions app on prToMain (exempting it
from the 1-review requirement) plus a separate requireTests ruleset
with no bypass actors, so the test check still gates the merge.

Requires two settings changes before this actually merges on its
own (see PR description) — until then it'll open PRs that wait for
manual merge, same as before.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
mbegin-robotiq and others added 2 commits September 22, 2026 10:50
test.yml can't gate the daily PR: GitHub doesn't trigger workflow runs
from events created by GITHUB_TOKEN, so the required check would never
report and --auto would never fire. Run the same tests as a step before
the PR is opened, and drop the planned requireTests ruleset.

Also fixes EXISTING_PR picking up the literal string "null", which would
have skipped gh pr create on the first run.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…les are satisfied

Replaces the ruleset-bypass approach, which can't work: "GitHub Actions"
isn't available as a bypass actor on this org, and a PR opened with
GITHUB_TOKEN never triggers test.yml, so its required check would never
report.

Instead the robotiq-readme-bot App opens the PR (a distinct actor, tied to
no personal account) and readme-auto-merge.yml approves it with
GITHUB_TOKEN and enables auto-merge — the same two-actor arrangement that
merges Dependabot's PRs on robotiq.github.io. prToMain needs no changes at
all; every rule stays enforced against every actor.

Also adds a concurrency group and commits under the App's bot identity so
changes are attributed.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@mbegin-robotiq mbegin-robotiq changed the title feat: fully automatic daily README update, no PAT feat: fully automatic daily README update via a GitHub App Sep 22, 2026

@mbegin-robotiq mbegin-robotiq left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the App-based design. Verified: the private key mints an installation token scoped to robotiq/.github only; all three workflows parse; tests pass 16/16; readme-auto-merge.yml has no checkout step; and its actor/branch gate correctly skipped on this PR. prToMain is unchanged — no bypass actors, all rules still enforced.

@mbegin-robotiq
mbegin-robotiq merged commit 62d65eb into main Sep 22, 2026
2 checks passed
@mbegin-robotiq
mbegin-robotiq deleted the bypass-actor-no-pat branch September 22, 2026 15:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants