Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

repo sync #4397

Merged
merged 2 commits into from
Mar 9, 2021
Merged

repo sync #4397

merged 2 commits into from
Mar 9, 2021

Conversation

Octomerger
Copy link
Contributor

This is an automated pull request to sync changes between the public and private repos.

🤖 This pull request should be merged (not squashed) to preserve continuity across repos, so please let a bot do the merging!

Octomerger and others added 2 commits March 9, 2021 08:38
#17918)

* adding workflows note about dependabot token

* reworded a little to make active

* Update data/reusables/actions/workflow-runs-dependabot-note.md

Co-authored-by: Shati Patel <42641846+shati-patel@users.noreply.github.com>

Co-authored-by: Shati Patel <42641846+shati-patel@users.noreply.github.com>
@Octomerger Octomerger added automated-reposync-pr Auto label for repo sync automerge labels Mar 8, 2021
@github-actions github-actions bot added the triage Do not begin working on this issue until triaged by the team label Mar 8, 2021
@Octomerger Octomerger merged commit d01d0ad into main Mar 9, 2021
@github-actions
Copy link
Contributor

github-actions bot commented Mar 9, 2021

Thanks very much for contributing! Your pull request has been merged 🎉 You should see your changes appear on the site in approximately 24 hours. If you're looking for your next contribution, check out our help wanted issues

Copy link

@simoneb simoneb left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@runleonarun Hi Leona, this change broke all our integrations via a GitHub action that automatically merged Dependabot pull requests using the built-in GITHUB_TOKEN. Is there a way to reach out to somebody about this change?

@runleonarun
Copy link
Contributor

@simoneb Let me find someone who can help!

@simoneb
Copy link

simoneb commented Mar 9, 2021

@simoneb Let me find someone who can help!

It's sorted already, thank you and apologies for bothering you

@runleonarun
Copy link
Contributor

It's sorted already, thank you and apologies for bothering you

@simoneb I'm so relieved to hear that!

@WtfJoke
Copy link

WtfJoke commented Mar 10, 2021

We have exactly the same problem (our dependabot pull requests cant access secrets anymore and cant install the dependencies from our private registry).
Can you please help us, too :D

Or how did you sorted it out @simoneb

@simoneb
Copy link

simoneb commented Mar 10, 2021

@WtfJoke "sorted", it's now the default behavior that the GITHUB_TOKEN is readonly, so you'll have to find workarounds. See the announcement here https://github.blog/changelog/2021-02-19-github-actions-workflows-triggered-by-dependabot-prs-will-run-with-read-only-permissions/.

Very useful information about alternatives and workarounds here https://github.com/peter-evans/create-pull-request/blob/master/docs/concepts-guidelines.md

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
automated-reposync-pr Auto label for repo sync triage Do not begin working on this issue until triaged by the team
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants