Skip to content

Move shared workflow automation away from member-owned PATs #186

Description

@redeboer

Move shared workflow automation away from member-owned PATs. Installed GitHub Apps should create upgrade PRs and automated fix commits under bot identities, with credentials maintained centrally. Use the built-in GITHUB_TOKEN wherever sufficient, and avoid forwarding unrelated secrets to reusable workflows.

Completion means the linked work supports public and private repositories, preserves fork-PR behavior, and survives policy regeneration without restoring PATs or requiring workflow checks to be disabled. Document app ownership, permissions, credential maintenance, and caller migration. Codecov authentication and cross-repository benchmark publishing remain separate.

Related work: ComPWA/policy#594 (unreliable Dependabot triggers), ComPWA/policy#694 (prek migration), ComPWA/compwa.github.io#313 (developer guidance), and ComPWA/policy#56 (project-board enrollment).

Background: #177, ComPWA/policy#346, and ComPWA/policy#565.

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

💥 EpicCollection of issues

Type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions