Repository navigation
ci: run dependency PR checks with a GitHub App - #265
Merged
Merged
Conversation
There was a problem hiding this comment.
No issues found across 3 files
Confidence score: 5/5
- Automated review surfaced no issues in the provided summaries.
- No files require special attention.
Shadow auto-approve: would require human review. Switches dependency-PR automation from GITHUB_TOKEN to an org-owned GitHub App token and narrows workflow permissions; this changes CI authentication/access control and depends on external App/secret setup, so human sign-off is needed.
Re-trigger cubic
Contributor
📊 Test Coverage ReportCurrent Statement Coverage: Coverage Change: ✅ No change Statement Coverage by PackageGo measures covered statements. Codecov measures fully covered lines, so its percentage can differ.
📋 Detailed Coverage by Function (click to expand)
Generated by GitHub Actions |
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
Automated submodule dependency PRs are created with
GITHUB_TOKEN, which makes GitHub require approval before their PR workflows run. This required manual intervention on #261.What changed
GITHUB_TOKENto Contents read-only..github/README.md.go.work, and disable automatic toolchain upgrades. Local CI was selecting Homebrew's Go 1.27.1, which the installed linter could not analyse.Review notes
speakeasy-api/openapi.BOT_APP_CLIENT_IDandBOT_APP_PRIVATE_KEYare configured as a repository variable and secret respectively.Testing
mise ci: passed locally with Go 1.26.0, including lint, tests, CLI integration tests, and build. The initial run on Go 1.27.1 failed in the installed linter; pinning the declared minimum resolved it.speakeasy-api/openapi, then revoked it.actionlint: passed with shellcheck disabled and only two stale bundled-metadata warnings excluded. Verified the actualactions/create-github-app-token@v3action definition supportsclient-idand does not require the deprecatedapp-idinput.git diff --check: passed.Summary by cubic
Makes automated submodule dependency PRs start their checks without manual approval by creating them with a token from an organisation-owned GitHub App instead of
GITHUB_TOKEN.GITHUB_TOKENto read-only Contents access..github/README.md.GOTOOLCHAIN=localso local CI uses the declared minimum Go version instead of the newer one Homebrew selects.Written for commit 8e89a74. Summary will update on new commits.