fix(ci): use PAT for release-plz PR creation - #5
Conversation
GITHUB_TOKEN is blocked by default from creating PRs. Use the same GH_TOKEN PAT for both release and release-pr jobs. 🤖 Generated with AI
|
Important Review skippedReview was skipped due to path filters ⛔ Files ignored due to path filters (1)
CodeRabbit blocks several paths by default. You can override this behavior by explicitly including those paths in the path filters. For example, including You can disable this status message by setting the Use the checkbox below for a quick retry:
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Pull request overview
Updates the release automation workflow so release-plz-pr uses a PAT (via secrets.GH_TOKEN) when creating release PRs, avoiding GitHub’s repo setting requirement that otherwise blocks PR creation with GITHUB_TOKEN.
Changes:
- Switch
release-plz-prjob’sGITHUB_TOKENenv value from the built-in token tosecrets.GH_TOKEN(PAT). - Add inline documentation explaining why the PAT is required for PR creation.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | ||
| # PAT is required to create PRs without enabling | ||
| # "Allow GitHub Actions to create pull requests" in repo settings. | ||
| GITHUB_TOKEN: ${{ secrets.GH_TOKEN }} |
There was a problem hiding this comment.
This switches PR creation to a PAT stored in secrets.GH_TOKEN. To reduce blast radius, it would be good to document (in this comment or repo docs) the minimum required scopes/permissions for that token (preferably a fine-grained PAT limited to this repo) and ensure it’s not a broadly-scoped classic PAT.
| env: | ||
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | ||
| # PAT is required to create PRs without enabling | ||
| # "Allow GitHub Actions to create pull requests" in repo settings. |
There was a problem hiding this comment.
The repo setting name in this comment looks outdated/inaccurate. On GitHub it’s currently labeled “Allow GitHub Actions to create and approve pull requests”, so referencing the exact wording (or linking to the setting path) would avoid confusion for maintainers trying to follow this guidance.
| # "Allow GitHub Actions to create pull requests" in repo settings. | |
| # the "Allow GitHub Actions to create and approve pull requests" repo setting. |
🤖 Generated with AI
Summary
Test plan
🤖 Generated with AI