Move shared workflow automation away from member-owned PATs. Installed GitHub Apps should create upgrade PRs and automated fix commits under bot identities, with credentials maintained centrally. Use the built-in GITHUB_TOKEN wherever sufficient, and avoid forwarding unrelated secrets to reusable workflows.
Completion means the linked work supports public and private repositories, preserves fork-PR behavior, and survives policy regeneration without restoring PATs or requiring workflow checks to be disabled. Document app ownership, permissions, credential maintenance, and caller migration. Codecov authentication and cross-repository benchmark publishing remain separate.
Related work: ComPWA/policy#594 (unreliable Dependabot triggers), ComPWA/policy#694 (prek migration), ComPWA/compwa.github.io#313 (developer guidance), and ComPWA/policy#56 (project-board enrollment).
Background: #177, ComPWA/policy#346, and ComPWA/policy#565.
Move shared workflow automation away from member-owned PATs. Installed GitHub Apps should create upgrade PRs and automated fix commits under bot identities, with credentials maintained centrally. Use the built-in
GITHUB_TOKENwherever sufficient, and avoid forwarding unrelated secrets to reusable workflows.Completion means the linked work supports public and private repositories, preserves fork-PR behavior, and survives policy regeneration without restoring PATs or requiring workflow checks to be disabled. Document app ownership, permissions, credential maintenance, and caller migration. Codecov authentication and cross-repository benchmark publishing remain separate.
Related work: ComPWA/policy#594 (unreliable Dependabot triggers), ComPWA/policy#694 (prek migration), ComPWA/compwa.github.io#313 (developer guidance), and ComPWA/policy#56 (project-board enrollment).
Background: #177, ComPWA/policy#346, and ComPWA/policy#565.