fix(ci): enable release-PR auto-merge with the PAT, not GITHUB_TOKEN
Auto-merge enabled via GITHUB_TOKEN attributes the eventual merge commit to github-actions[bot], so recursion prevention suppresses the resulting push to main — the follow-up release-please run that cuts the tag/release never fires. Net: the version PR merges but no release/tag/images are ever produced (#719). Enable auto-merge with RELEASE_PLEASE_TOKEN instead (a real identity) so the merge triggers the tag-cutting run. Approval stays on GITHUB_TOKEN because it must be a different identity than the PR author (the PAT) to count as a review. Observed on #723: merged 3.77.3-beta.0 but no run followed and no tag was cut.
This commit is contained in:
@@ -44,8 +44,11 @@ jobs:
|
||||
fi
|
||||
pr=$(gh pr list --head release-please--branches--stable --state open --json number --jq '.[0].number // empty')
|
||||
if [ -n "$pr" ]; then
|
||||
# Approve as github-actions[bot] (GITHUB_TOKEN, ≠ the PAT author) so it
|
||||
# is a valid review; enable auto-merge as the PAT so the merge commit is
|
||||
# attributed to a real identity and triggers the tag-cutting run (#719).
|
||||
gh pr review "$pr" --approve --body "Automated approval — release-please version bump + changelog (#719)." || true
|
||||
gh pr merge "$pr" --squash --auto || true
|
||||
GH_TOKEN="$RELEASE_PAT" gh pr merge "$pr" --squash --auto || true
|
||||
else
|
||||
echo "No open release PR to auto-merge."
|
||||
fi
|
||||
|
||||
Reference in New Issue
Block a user