ci: use GitHub App token to open upstream-ledger-sync PR (#165)

The built-in GITHUB_TOKEN cannot open the sync PR: the enterprise policy
blocks GitHub Actions from creating/approving pull requests, which
overrides the org and repo settings. That restriction applies only to
github-actions[bot], so mint a PROMOTE_APP installation token and pass
it to create-pull-request, mirroring promote-to-main.yml.
This commit is contained in:
Adam Moussa 2026-07-10 12:25:59 -04:00 • committed by GitHub
parent 2072da9169
commit 51fbf75c3f
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -33,9 +33,22 @@ jobs:
- name: Sync ledger
run: python3 scripts/triage.py sync
# The built-in GITHUB_TOKEN cannot open PRs: the enterprise policy blocks
# "GitHub Actions creating/approving pull requests" and overrides org+repo.
# That restriction applies only to github-actions[bot], so we mint a GitHub
# App installation token instead. PROMOTE_APP must carry pull-requests:write
# + contents:write on this repo.
- name: Mint app token for the bot PR
id: app-token
uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0
with:
app-id: ${{ secrets.PROMOTE_APP_ID }}
private-key: ${{ secrets.PROMOTE_APP_PRIVATE_KEY }}
- name: Open/refresh PR if the ledger changed
uses: peter-evans/create-pull-request@v7
with:
token: ${{ steps.app-token.outputs.token }}
base: dev
branch: bot/upstream-ledger-sync
commit-message: "chore: sync upstream triage ledger"