You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The catalog publisher and consumer synchronizer need to:
read/write branches in LibreCodeCoop/.github and managed consumer repositories;
create/update pull requests across repositories.
The first real runs failed early because WORKFLOW_UPDATE_TOKEN is not configured in LibreCodeCoop/github-workflows.
Preferred credential model
Prefer a dedicated GitHub App installation credential over a personal access token when practical.
The credential should have only the permissions required for managed repositories, typically:
Contents: read/write;
Pull requests: read/write;
Metadata: read.
Repository access should be limited to:
LibreCodeCoop/.github;
declared consumer repositories;
additional repositories only when they are explicitly onboarded.
If a repository/organization secret named WORKFLOW_UPDATE_TOKEN is used initially, it must provide equivalent scoped access and must not be tied to a developer's everyday personal token.
Acceptance criteria
the credential is available to LibreCodeCoop/github-workflows;
catalog publication can checkout and open a PR in LibreCodeCoop/.github;
consumer synchronization can checkout and open a PR in LibreCodeCoop/extract;
no broader organization write access is granted than required;
credential setup/rotation ownership is documented.
Validation
After configuration:
manually run Publish workflow catalog and confirm a no-op run creates no PR;
manually run Sync consumer workflows and confirm the initial extract adoption PR is created;
merge the adoption lock PR and run again to confirm no-op behavior.
Latest production validation
The blocker is still active as of 2026-09-20.
scheduled Sync consumer workflows run 35502360899 failed at the Validate workflow update token preflight;
the runner saw WORKFLOW_UPDATE_TOKEN as empty;
the most recent Publish workflow catalog push run failed at the same preflight;
no downstream checkout, mutation or partial publication occurred.
This confirms the current failure mode is intentional and fail-closed. There is no new workflow regression to fix before configuring the credential.
Next operational step
Configure the scoped cross-repository credential for LibreCodeCoop/github-workflows, then:
run Publish workflow catalog manually and confirm the current catalog produces no unexpected diff/PR;
Parent: #11
Related: #12, #13
Context
The catalog publisher and consumer synchronizer need to:
LibreCodeCoop/.githuband managed consumer repositories;The first real runs failed early because
WORKFLOW_UPDATE_TOKENis not configured inLibreCodeCoop/github-workflows.Preferred credential model
Prefer a dedicated GitHub App installation credential over a personal access token when practical.
The credential should have only the permissions required for managed repositories, typically:
Repository access should be limited to:
LibreCodeCoop/.github;If a repository/organization secret named
WORKFLOW_UPDATE_TOKENis used initially, it must provide equivalent scoped access and must not be tied to a developer's everyday personal token.Acceptance criteria
LibreCodeCoop/github-workflows;LibreCodeCoop/.github;LibreCodeCoop/extract;Validation
After configuration:
extractadoption PR is created;Latest production validation
The blocker is still active as of 2026-09-20.
Validate workflow update tokenpreflight;WORKFLOW_UPDATE_TOKENas empty;This confirms the current failure mode is intentional and fail-closed. There is no new workflow regression to fix before configuring the credential.
Next operational step
Configure the scoped cross-repository credential for
LibreCodeCoop/github-workflows, then:LibreCodeCoop/extractadoption/lock PR;Completed validation
The GitHub App path is now validated in production:
LibreCodeCoop/.github;LibreCodeCoop/extract;librecode-workflow-automation[bot];docs/cross-repository-automation.md.Implementation: #35
Documentation: #37