Conversation
main is what customers clone, so .github/workflows is now empty. The golden snapshot request it served moves inline into sync.yml on the template branch, where the pushed main SHA is already in hand. Merge the template-branch change first; until it lands the sync still dispatches this workflow by name.
Contributor
Author
|
Wrong approach — |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Step 2 of emptying
main's.github/workflows. After this, the directory is empty.Why
mainis what customers clone. Anything under.github/workflowshere either leaks Builder-internal automation into customer repos or — because the Builder GitHub App has noworkflowspermission — blocks them from pushing when they migrate to their own remote.What
Delete
create-template-snapshot.yml. Its golden snapshot request moves inline intosync.ymlon thetemplatebranch.The sync preserves
main's own.githubacross merges (git checkout HEAD -- .github), so this deletion sticks.Ordering
Merge after the companion
templatePR. Until that lands,sync.ymlstill dispatches this workflow by name and will fail without it.Related
One investigation, four PRs. A customer hit
refusing to allow a GitHub App to create or update workflow ... withoutworkflowspermissionwhen migrating an Agent Native project to their own GitHub repo. Root cause: goldens were shipping the starter's workflow files into customer repos..githubscrub runsfusion-git-sha)template)main)main6341 and 6342 are independent. 406 must merge before 407.
Not addressed here: the Builder GitHub App manifest requests
contents: writebut notworkflows, so it cannot push any.github/workflows/**change to a customer repo. That is a separate permission decision.