From 280e1269b75f94c424edb4424b7e22c55748161e Mon Sep 17 00:00:00 2001 From: finalerock44 <77282157+finalerock44@users.noreply.github.com> Date: Wed, 24 Jun 2026 15:11:14 +0100 Subject: [PATCH 1/2] fix(ci): keep dependabot and fork PRs green Dependabot/fork PRs run without repo secrets, so three jobs failed on them: - lint-and-test: HAS_PRIVATE_ACCESS was true for dependabot (same-repo head), so it tried to clone the private mock-api with an empty DCD_SSH_DEPLOY_KEY. Now excludes dependabot[bot], same as forks (skips mock-api + integration). - claude-code-review: skips dependabot/fork PRs (no CLAUDE_CODE_OAUTH_TOKEN). - cla: skips its action step until PERSONAL_ACCESS_TOKEN is configured so the check is green instead of 'Branch cla-signatures not found'; also fixes two invalid input names (custom-*-prompt -> custom-*-prcomment). --- .github/workflows/cla.yml | 11 +++++++++-- .github/workflows/claude-code-review.yml | 10 ++++------ .github/workflows/cli-ci.yml | 6 +++++- 3 files changed, 18 insertions(+), 9 deletions(-) diff --git a/.github/workflows/cla.yml b/.github/workflows/cla.yml index bcab57c..215c76b 100644 --- a/.github/workflows/cla.yml +++ b/.github/workflows/cla.yml @@ -30,10 +30,17 @@ permissions: jobs: cla: runs-on: ubuntu-latest + # Empty until the PERSONAL_ACCESS_TOKEN secret is configured (see SETUP above). + # While empty, the action step below is skipped so this check passes (green) + # instead of failing on every PR with "Branch cla-signatures not found". It + # auto-activates once the secret + cla-signatures branch exist. + env: + HAS_CLA_TOKEN: ${{ secrets.PERSONAL_ACCESS_TOKEN != '' }} # Only act on the signature comment or on PR events (not every comment). if: (github.event.issue.pull_request && contains(github.event.comment.body, 'I have read the CLA Document and I hereby sign the CLA')) || github.event_name == 'pull_request_target' steps: - uses: contributor-assistant/github-action@v2.6.1 + if: env.HAS_CLA_TOKEN == 'true' env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} PERSONAL_ACCESS_TOKEN: ${{ secrets.PERSONAL_ACCESS_TOKEN }} @@ -44,6 +51,6 @@ jobs: # PR target branches the CLA applies to. allowlist: dependabot[bot],renovate[bot],*[bot] # Customise the bot's prompts if desired: - custom-notsigned-prompt: "Thanks for your contribution! Please sign our Contributor License Agreement before we can merge. Comment the line below to sign:" + custom-notsigned-prcomment: "Thanks for your contribution! Please sign our Contributor License Agreement before we can merge. Comment the line below to sign:" custom-pr-sign-comment: "I have read the CLA Document and I hereby sign the CLA" - custom-allsigned-prompt: "All contributors have signed the CLA. ✍️ ✅" + custom-allsigned-prcomment: "All contributors have signed the CLA. ✍️ ✅" diff --git a/.github/workflows/claude-code-review.yml b/.github/workflows/claude-code-review.yml index c396185..5474be8 100644 --- a/.github/workflows/claude-code-review.yml +++ b/.github/workflows/claude-code-review.yml @@ -12,12 +12,10 @@ on: jobs: claude-review: - # Optional: Filter by PR author - # if: | - # github.event.pull_request.user.login == 'external-contributor' || - # github.event.pull_request.user.login == 'new-developer' || - # github.event.pull_request.author_association == 'FIRST_TIME_CONTRIBUTOR' - + # The review needs CLAUDE_CODE_OAUTH_TOKEN, which is NOT exposed to PRs that + # run without secrets — Dependabot PRs and PRs from forks. Skip them so the + # check doesn't fail with an empty token; same-repo PRs only. + if: ${{ github.event.pull_request.head.repo.full_name == github.repository && github.actor != 'dependabot[bot]' }} runs-on: ubuntu-latest permissions: contents: read diff --git a/.github/workflows/cli-ci.yml b/.github/workflows/cli-ci.yml index d4bb529..9febaea 100644 --- a/.github/workflows/cli-ci.yml +++ b/.github/workflows/cli-ci.yml @@ -40,8 +40,12 @@ jobs: # SSH deploy key. GitHub does NOT expose secrets to pull_request workflows # triggered from forks, so that checkout (and the integration tests that need # it) can only run for same-repo events. Fork PRs still run lint/typecheck/build. + # + # Dependabot PRs branch from this repo (so the fork check passes) but ALSO run + # without secrets — treat them like forks and skip the private checkout, or + # the mock-api clone fails with an empty DCD_SSH_DEPLOY_KEY. env: - HAS_PRIVATE_ACCESS: ${{ github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository }} + HAS_PRIVATE_ACCESS: ${{ (github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository) && github.actor != 'dependabot[bot]' }} steps: - name: Checkout CLI From 095c235152381827d45107c8f22e4b14b92bc7a0 Mon Sep 17 00:00:00 2001 From: finalerock44 <77282157+finalerock44@users.noreply.github.com> Date: Wed, 24 Jun 2026 15:19:53 +0100 Subject: [PATCH 2/2] ci: group all github-actions bumps into one weekly PR Wildcard pattern so major action bumps join the group too, instead of one PR per action. --- .github/dependabot.yml | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index e792454..e93cbd3 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -28,7 +28,8 @@ updates: commit-message: prefix: ci groups: + # One PR per week for ALL action bumps (including majors). Actions are + # low-risk and quick to eyeball together; no need for a PR each. actions: - update-types: - - minor - - patch + patterns: + - "*"