open-swe/.github/workflows/upstream-ledger-sync.yml
Adam Moussa 51fbf75c3f
ci: use GitHub App token to open upstream-ledger-sync PR (#165)
The built-in GITHUB_TOKEN cannot open the sync PR: the enterprise policy
blocks GitHub Actions from creating/approving pull requests, which
overrides the org and repo settings. That restriction applies only to
github-actions[bot], so mint a PROMOTE_APP installation token and pass
it to create-pull-request, mirroring promote-to-main.yml.
2026-07-10 12:25:59 -04:00

61 lines
No EOL
2 KiB
YAML

name: Upstream Ledger Sync
on:
schedule:
- cron: "17 12 * * *" # daily ~08:17 ET
workflow_dispatch:
concurrency:
group: upstream-ledger-sync
cancel-in-progress: false
permissions:
contents: write
pull-requests: write
jobs:
sync:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
with:
ref: dev
fetch-depth: 0
- name: Add upstream remote
run: |
git remote add upstream https://github.com/langchain-ai/open-swe.git || true
- uses: actions/setup-python@v5
with:
python-version: "3.12"
- name: Sync ledger
run: python3 scripts/triage.py sync
# The built-in GITHUB_TOKEN cannot open PRs: the enterprise policy blocks
# "GitHub Actions creating/approving pull requests" and overrides org+repo.
# That restriction applies only to github-actions[bot], so we mint a GitHub
# App installation token instead. PROMOTE_APP must carry pull-requests:write
# + contents:write on this repo.
- name: Mint app token for the bot PR
id: app-token
uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0
with:
app-id: ${{ secrets.PROMOTE_APP_ID }}
private-key: ${{ secrets.PROMOTE_APP_PRIVATE_KEY }}
- name: Open/refresh PR if the ledger changed
uses: peter-evans/create-pull-request@v7
with:
token: ${{ steps.app-token.outputs.token }}
base: dev
branch: bot/upstream-ledger-sync
commit-message: "chore: sync upstream triage ledger"
title: "chore: sync upstream triage ledger"
body: |
Automated 'scripts/triage.py sync'. New rows land as **Untriaged** - triage each (adopt/defer/won't-merge) before merging.
labels: upstream-sync
add-paths: |
docs/upstream-sync/triage.jsonl
docs/upstream-sync/triage.md