diff --git a/.github/workflows/upstream-ledger-sync.yml b/.github/workflows/upstream-ledger-sync.yml index 837c74db..fc44f09e 100644 --- a/.github/workflows/upstream-ledger-sync.yml +++ b/.github/workflows/upstream-ledger-sync.yml @@ -33,9 +33,22 @@ jobs: - name: Sync ledger run: python3 scripts/triage.py sync + # The built-in GITHUB_TOKEN cannot open PRs: the enterprise policy blocks + # "GitHub Actions creating/approving pull requests" and overrides org+repo. + # That restriction applies only to github-actions[bot], so we mint a GitHub + # App installation token instead. PROMOTE_APP must carry pull-requests:write + # + contents:write on this repo. + - name: Mint app token for the bot PR + id: app-token + uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0 + with: + app-id: ${{ secrets.PROMOTE_APP_ID }} + private-key: ${{ secrets.PROMOTE_APP_PRIVATE_KEY }} + - name: Open/refresh PR if the ledger changed uses: peter-evans/create-pull-request@v7 with: + token: ${{ steps.app-token.outputs.token }} base: dev branch: bot/upstream-ledger-sync commit-message: "chore: sync upstream triage ledger"