Skip to content

fix: use scoped PAT for dist/ regenerate auto-PR, not default GITHUB_TOKEN - #137

Merged
chaksaray merged 1 commit into
developfrom
fix/dist-sync-pr-token
Aug 7, 2026
Merged

chaksaray merged 1 commit into
developfrom
fix/dist-sync-pr-token

Conversation

@chaksaray

Copy link
Copy Markdown
Contributor

Problem

The regenerate-records-json workflow has failed on every single run
since at least 2026-07-28 (11 consecutive failures) at its "Open PR if
dist/ changed" step:

##[error]GitHub Actions is not permitted to create or approve pull requests.

peter-evans/create-pull-request@v8 had no token: input, so it fell
back to the default GITHUB_TOKEN. This repo has "Allow GitHub Actions
to create and approve pull requests" off (confirmed via
gh api repos/aveproject/ave/actions/permissions/workflow ->
can_approve_pull_request_reviews: false), which hard-gates PR creation
regardless of the permissions: block declared in the workflow YAML.

Fix

Point only the PR-creation step at DIST_SYNC_PR_TOKEN, a fine-grained
PAT scoped to aveproject/ave only (contents + pull requests:
read/write, real expiration set, nothing else). This is narrower than
flipping the repo-wide toggle, which would hand every workflow in this
repo PR-creation rights it doesn't need. Earlier steps (checkout,
npm ci, build-records.js) are untouched and keep using the default
GITHUB_TOKEN.

Verification

Can't fully verify until this merges to develop -- the workflow only
triggers on push to develop touching records/. Once merged, the next
records/ change landing on develop (e.g. the pending AVE-2026-00075
PR) will be the real end-to-end trigger. Flagging that as the follow-up
check rather than claiming it's proven green here.

…TOKEN

The regenerate-records-json workflow has been failing on every run since
at least 2026-07-28 ('GitHub Actions is not permitted to create or
approve pull requests') -- the repo's 'Allow GitHub Actions to create
and approve pull requests' setting is off, which blocks
peter-evans/create-pull-request when it falls back to the default
GITHUB_TOKEN, and that setting is deliberately left off repo-wide so no
other workflow picks up PR-creation rights it doesn't need.

Point only this step at DIST_SYNC_PR_TOKEN, a fine-grained PAT scoped
to this repo (contents + pull-requests: read/write, nothing else).
Earlier steps (checkout, npm ci, build-records.js) keep using the
default GITHUB_TOKEN.
@chaksaray
chaksaray merged commit c6761de into develop Aug 7, 2026
6 checks passed
@chaksaray
chaksaray deleted the fix/dist-sync-pr-token branch August 9, 2026 16:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant