Skip to content

fix: use PARENT_REPO_PAT for sync commits to protected main - #42

Merged
mateodelnorte merged 1 commit into
mainfrom
fix/sync-workflow-pat
Mar 5, 2026
Merged

mateodelnorte merged 1 commit into
mainfrom
fix/sync-workflow-pat

Conversation

@mateodelnorte

@mateodelnorte mateodelnorte commented Mar 5, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Switch on-child-update.yml from REPO_WRITE_PACKAGES_PAT to org-level PARENT_REPO_PAT
  • Fixes branch protection rejection when syncing child repo commits to main

Context

Failed run: https://github.com/harmony-labs/meta/actions/runs/22697487943/job/65807070288

REPO_WRITE_PACKAGES_PAT can't bypass branch protection. PARENT_REPO_PAT is the org-level PAT already used by gitkb-core for the same purpose.

Test plan

  • Re-run the failed sync workflow after merge

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores
    • Updated authentication configuration in the continuous integration workflow to use a different access token for repository operations.

REPO_WRITE_PACKAGES_PAT doesn't have permission to bypass branch
protection rules. Switch to PARENT_REPO_PAT (org-level secret) which
is the same PAT used by gitkb-core for cross-repo operations.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Mar 5, 2026 •

Copy link
Copy Markdown

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro

Run ID: f8c88276-f9aa-4ce7-be3c-697e6099d948

📥 Commits

Reviewing files that changed from the base of the PR and between 6ef38bb and 370eb3f.

📒 Files selected for processing (1)
  • .github/workflows/on-child-update.yml

Walkthrough

GitHub Actions workflow updated to swap the authentication secret used during repository checkout, replacing REPO_WRITE_PACKAGES_PAT with PARENT_REPO_PAT in the on-child-update workflow.

Changes

Cohort / File(s) Summary
Workflow Authentication
.github/workflows/on-child-update.yml
Checkout step secret updated from REPO_WRITE_PACKAGES_PAT to PARENT_REPO_PAT; authentication credential source modified without altering workflow logic or behavior.

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~2 minutes

Poem

🐰 A secret swap, so quick and clean,
From one PAT to another seen,
The workflow hops with fresh credentials,
No logic bent, just essentials! ✨

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch fix/sync-workflow-pat

Comment @coderabbitai help to get the list of available commands and usage tips.

@greptile-apps

greptile-apps Bot commented Mar 5, 2026

Copy link
Copy Markdown

Greptile Summary

This PR makes a targeted, single-line fix to .github/workflows/on-child-update.yml, replacing the REPO_WRITE_PACKAGES_PAT secret with PARENT_REPO_PAT in the actions/checkout@v4 step. Because actions/checkout embeds the provided token into the git remote URL, all subsequent git push calls in the same job inherit that credential — making this the correct place to swap the token so the push to the protected main branch succeeds.

Key changes:

  • token: ${{ secrets.REPO_WRITE_PACKAGES_PAT }} → token: ${{ secrets.PARENT_REPO_PAT }} in the checkout step (line 40)

Notes:

  • The fix is consistent with how PARENT_REPO_PAT is used in gitkb-core for the same purpose (bypassing branch protection on main).
  • No other steps in the workflow reference the old secret, so the change is complete.
  • The PARENT_REPO_PAT is a higher-privilege org-level token; it is used here only in a workflow triggered by repository_dispatch, which requires write access to the repository to invoke — limiting the blast radius of any misuse.

Confidence Score: 5/5

  • This PR is safe to merge — it is a minimal, well-reasoned one-line credential swap that directly addresses a documented branch-protection failure.
  • The change is a single token substitution in a checkout step, backed by a clear failure trace and aligned with existing practice in the org. There are no logic changes, no new surfaces introduced, and the trigger mechanism (repository_dispatch) already requires write access, limiting exposure of the elevated token.
  • No files require special attention.

Important Files Changed

Filename Overview
.github/workflows/on-child-update.yml Single-line change swapping REPO_WRITE_PACKAGES_PAT for PARENT_REPO_PAT in the checkout step so the subsequent git push to protected main is authorized.

Sequence Diagram

sequenceDiagram
    participant ChildRepo as Child Repo Workflow
    participant GH as GitHub API
    participant Workflow as on-child-update.yml
    participant Main as Protected main branch

    ChildRepo->>GH: repository_dispatch (child-repo-updated)
    GH->>Workflow: Trigger job: create-sync-commit
    Workflow->>GH: actions/checkout@v4 with org-level token
    GH-->>Workflow: Repo checked out with elevated credentials

    Workflow->>Workflow: Extract payload (repo_name, short_sha, message, type, actor)
    Workflow->>Workflow: git config user name and email
    Workflow->>Workflow: git commit --allow-empty with sync message

    Workflow->>Main: git push using org-level token
    Note over Workflow,Main: Branch protection bypassed with correct token
    Main-->>Workflow: Push accepted

    Workflow->>Workflow: Log sync details
Loading

Last reviewed commit: 370eb3f

@mateodelnorte
mateodelnorte merged commit dc5c190 into main Mar 5, 2026
8 of 9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant