You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Let the reusable update-to-latest-easystats workflow use an optional caller-supplied token when it creates dependency update PRs.
Thanks to maintainers
Thanks for maintaining these shared workflows. The issue report and datawizard#640 example made the failure mode clear.
Issue or motivation
Closes#83. PRs created with the default GITHUB_TOKEN do not trigger the usual pull_request or push workflows, so the automated dependency-update PR can appear without CI checks.
Root cause
The workflow always passed secrets.GITHUB_TOKEN to peter-evans/create-pull-request. GitHub suppresses most workflow events caused by GITHUB_TOKEN, which prevents the generated PR from starting the package CI.
Change
Declare an optional EASYSTATS_BOT_TOKEN secret on the reusable workflow.
Use that token for create-pull-request when callers provide it, with github.token as the fallback to preserve current behavior.
Document the optional secret in README.Rmd and regenerate README.md.
R CMD check reports the same pre-existing 1 WARNING and 2 NOTEs on origin/main and on this branch: the CC0 license string, LICENSE top-level note, and .github hidden-directory note.
Scope
This only changes the token used to create the automated dependency PR and the README note for callers. It does not change the dependency-update logic, branch naming, PR title/body, labels, or any general-purpose workflow.
The check result is still the repository baseline: 1 WARNING and 2 NOTEs for the CC0 license string, top-level LICENSE, and included .github directory.
The current failing format-suggest job stops before formatting because pull_request_target refuses to check out fork PR code with allow-unsafe-pr-checkout: false. I have not changed that here, since it is a separate repository security-policy choice. This patch stays limited to letting callers provide a bot/PAT token for dependency-update PRs, while keeping github.token as the fallback.
Following up on the outstanding format-suggest result: the current-head run still fails at checkout, before formatting, because pull_request_target rejects checking out fork PR code with allow-unsafe-pr-checkout: false. I have left that security setting untouched. Is there a safe alternative CI path the maintainers would like me to use, or should the PR remain pending this workflow-side decision?
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Let the reusable
update-to-latest-easystatsworkflow use an optional caller-supplied token when it creates dependency update PRs.Thanks to maintainers
Thanks for maintaining these shared workflows. The issue report and
datawizard#640example made the failure mode clear.Issue or motivation
Closes #83. PRs created with the default
GITHUB_TOKENdo not trigger the usualpull_requestorpushworkflows, so the automated dependency-update PR can appear without CI checks.Root cause
The workflow always passed
secrets.GITHUB_TOKENtopeter-evans/create-pull-request. GitHub suppresses most workflow events caused byGITHUB_TOKEN, which prevents the generated PR from starting the package CI.Change
EASYSTATS_BOT_TOKENsecret on the reusable workflow.create-pull-requestwhen callers provide it, withgithub.tokenas the fallback to preserve current behavior.README.Rmdand regenerateREADME.md.Tests
actionlint .github/workflows/update-to-latest-easystats.yamlRscript -e 'rmarkdown::render("README.Rmd", quiet = TRUE)'R CMD build .R CMD check --no-manual workflows_0.1.0.tar.gzR CMD checkreports the same pre-existing 1 WARNING and 2 NOTEs onorigin/mainand on this branch: the CC0 license string,LICENSEtop-level note, and.githubhidden-directory note.Scope
This only changes the token used to create the automated dependency PR and the README note for callers. It does not change the dependency-update logic, branch naming, PR title/body, labels, or any general-purpose workflow.