Skip to content

fix: use PAT for release-please PR updates - #87

Merged
mateodelnorte merged 1 commit into
mainfrom
fix/release-please-pat-token
May 19, 2026
Merged

mateodelnorte merged 1 commit into
mainfrom
fix/release-please-pat-token

Conversation

@mateodelnorte

@mateodelnorte mateodelnorte commented May 19, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • pass the org automation PAT into release-please-action
  • keep the existing release dispatch token unchanged

Why

Release Please PR updates made with the default GITHUB_TOKEN do not trigger downstream CI on the generated release PR. Using the established PARENT_REPO_PAT secret lets future release-please branch updates trigger checks.

Validation

  • git diff --check

Summary by CodeRabbit

  • Chores
    • Updated release automation workflow configuration to enhance security measures for internal deployment processes.

Review Change Stack

@coderabbitai

coderabbitai Bot commented May 19, 2026 •

Copy link
Copy Markdown

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro

Run ID: b328110b-ba46-466b-8ab0-1db4502ff243

📥 Commits

Reviewing files that changed from the base of the PR and between 5c44f54 and 8ee668e.

📒 Files selected for processing (1)
  • .github/workflows/on-push-main.yml

Walkthrough

The pull request adds explicit token authentication to the release-please GitHub Action. The Release Please step in the on-push-main workflow now passes ${{ secrets.PARENT_REPO_PAT }} as the token input parameter to the googleapis/release-please-action@v4 action.

Changes

Release Please Token Configuration

Layer / File(s) Summary
Release Please PAT Token Configuration
.github/workflows/on-push-main.yml
The googleapis/release-please-action@v4 step now explicitly passes the PARENT_REPO_PAT secret as the token input parameter.

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~3 minutes

Poem

🐰 A token hops in, shy at first,
Then PARENT_REPO_PAT quenches workflow thirst,
One line, one key, one secret path,
Release-please's cleaner auth bath! ✨

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately describes the main change: passing a PAT token to release-please for PR updates, which is the core modification shown in the workflow file.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/release-please-pat-token

Comment @coderabbitai help to get the list of available commands and usage tips.

@mateodelnorte
mateodelnorte merged commit 6149471 into main May 19, 2026
10 checks passed
@mateodelnorte
mateodelnorte deleted the fix/release-please-pat-token branch May 19, 2026 04:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant