Skip to content

fix(ci): use PAT for release-plz PR creation - #5

Merged
km-tr merged 2 commits into
mainfrom
fix/release-plz-token
Feb 24, 2026
Merged

km-tr merged 2 commits into
mainfrom
fix/release-plz-token

Conversation

@km-tr

@km-tr km-tr commented Feb 24, 2026

Copy link
Copy Markdown
Owner

Summary

  • release-plz-prジョブでもGH_TOKEN(PAT)を使用するよう変更
  • GITHUB_TOKENではリポジトリ設定で「Allow GitHub Actions to create pull requests」を有効にしないとPR作成が403エラーになるため

Test plan

  • mainマージ後、release-plz-prジョブがPRを正常に作成できることを確認

🤖 Generated with AI

GITHUB_TOKEN is blocked by default from creating PRs. Use the same GH_TOKEN PAT for both release and release-pr jobs.

🤖 Generated with AI
Copilot AI review requested due to automatic review settings February 24, 2026 11:32
@km-tr km-tr self-assigned this Feb 24, 2026
@coderabbitai

coderabbitai Bot commented Feb 24, 2026

Copy link
Copy Markdown

Important

Review skipped

Review was skipped due to path filters

⛔ Files ignored due to path filters (1)
  • .github/workflows/release-plz.yml is excluded by !**/*.yml

CodeRabbit blocks several paths by default. You can override this behavior by explicitly including those paths in the path filters. For example, including **/dist/** will override the default block on the dist directory, by removing the pattern from both the lists.

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch fix/release-plz-token

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the release automation workflow so release-plz-pr uses a PAT (via secrets.GH_TOKEN) when creating release PRs, avoiding GitHub’s repo setting requirement that otherwise blocks PR creation with GITHUB_TOKEN.

Changes:

  • Switch release-plz-pr job’s GITHUB_TOKEN env value from the built-in token to secrets.GH_TOKEN (PAT).
  • Add inline documentation explaining why the PAT is required for PR creation.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
# PAT is required to create PRs without enabling
# "Allow GitHub Actions to create pull requests" in repo settings.
GITHUB_TOKEN: ${{ secrets.GH_TOKEN }}

Copilot AI Feb 24, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This switches PR creation to a PAT stored in secrets.GH_TOKEN. To reduce blast radius, it would be good to document (in this comment or repo docs) the minimum required scopes/permissions for that token (preferably a fine-grained PAT limited to this repo) and ensure it’s not a broadly-scoped classic PAT.

Copilot uses AI. Check for mistakes.
Comment thread .github/workflows/release-plz.yml Outdated
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
# PAT is required to create PRs without enabling
# "Allow GitHub Actions to create pull requests" in repo settings.

Copilot AI Feb 24, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The repo setting name in this comment looks outdated/inaccurate. On GitHub it’s currently labeled “Allow GitHub Actions to create and approve pull requests”, so referencing the exact wording (or linking to the setting path) would avoid confusion for maintainers trying to follow this guidance.

Suggested change
# "Allow GitHub Actions to create pull requests" in repo settings.
# the "Allow GitHub Actions to create and approve pull requests" repo setting.

Copilot uses AI. Check for mistakes.
@km-tr
km-tr merged commit 17ce958 into main Feb 24, 2026
10 checks passed
@km-tr km-tr mentioned this pull request Feb 24, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants