Skip to content

ci(github): use app token for dependabot merges - #142

Merged
ncipollina merged 2 commits into
mainfrom
ci/dependabot-app-token
Jul 22, 2026
Merged

ci(github): use app token for dependabot merges#142
ncipollina merged 2 commits into
mainfrom
ci/dependabot-app-token

Conversation

@ncipollina

Copy link
Copy Markdown
Contributor

Summary

Updates the Dependabot auto-merge workflow to use the LayeredCraft GitHub App token for approving and enabling auto-merge. This avoids using GITHUB_TOKEN for the merge operation so downstream workflows can run after Dependabot auto-merged changes land on main.

Changes

  • Adds a SHA-pinned actions/create-github-app-token step for semver patch/minor Dependabot PRs.
  • Uses the generated app token as GH_TOKEN for gh pr review --approve and gh pr merge --auto --squash.
  • Keeps dependabot/fetch-metadata on the default GITHUB_TOKEN.

Validation

  • Reviewed workflow syntax and token usage.
  • No build required; workflow-only change.

Notes for Reviewers

Requires the Actions secrets DEPENDABOT_AUTOMERGE_APP_ID and DEPENDABOT_AUTOMERGE_PRIVATE_KEY to be available to this repository.

@github-actions github-actions Bot added the type: ci CI/CD changes label Jul 22, 2026
@ncipollina
ncipollina merged commit f84d061 into main Jul 22, 2026
5 checks passed
@ncipollina
ncipollina deleted the ci/dependabot-app-token branch July 22, 2026 19:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

type: ci CI/CD changes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant