Skip to content

[BUG](ci) Open uv-lock-refresh PRs as overture-pull-requester - #732

Merged
John McCall (lowlydba) merged 3 commits into
mainfrom
lowlydba-fix-ci-failure
Sep 11, 2026
Merged

John McCall (lowlydba) merged 3 commits into
mainfrom
lowlydba-fix-ci-failure

Conversation

@lowlydba

Copy link
Copy Markdown
Contributor

What

uv-lock-refresh.yml now generates a token via actions/create-github-app-token (the overture-pull-requester app, same client-id/secret as rebase-vnext.yaml) and passes it to create-pull-request, instead of the implicit GITHUB_TOKEN.

Why

#729 fixed the workflow's PR-creation permission, but the resulting PR (#730) is stuck: every check passes except the required "OMF PR Check" linked-issue check, since a scheduled lockfile refresh has no issue to link. overture-pull-requester has a bypass for that check (it's how the vnext force-rebase clears it), and using an app token also means the PR triggers CI normally, unlike a GITHUB_TOKEN-authored one.

Fixes #731

Testing

  • zizmor .github/workflows/uv-lock-refresh.yml — no findings.
  • YAML validated with yaml.safe_load.
  • Not run end-to-end (requires the scheduled/workflow_dispatch trigger); will confirm on the next run.

The default GITHUB_TOKEN can't clear the required 'OMF PR Check'
linked-issue check, so uv-lock-refresh PRs (which have no issue to
link) got stuck once #729 fixed the PR-creation permission. Use the
overture-pull-requester app -- already used for the vnext rebase --
which has a bypass for that check.

Fixes #731

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Signed-off-by: John McCall <john@overturemaps.org>
@github-actions

github-actions Bot commented Sep 10, 2026 •

Copy link
Copy Markdown

🗺️ Schema reference docs preview is live!

🌍 Preview https://staging.overturemaps.org/schema/pr/732/schema/index.html
🕐 Updated Sep 10, 2026 18:17 UTC
📝 Commit dd38453
🔧 env SCHEMA_PREVIEW true

Note

♻️ This preview updates automatically with each push to this PR.

@lowlydba
John McCall (lowlydba) marked this pull request as ready for review September 10, 2026 15:38
@lowlydba
John McCall (lowlydba) requested a review from a team as a code owner September 10, 2026 15:38
Copilot AI lite review requested due to automatic review settings September 10, 2026 15:38

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The workflow still checks out with GITHUB_TOKEN (despite the stated fix for #731) and the new bot sign-off email is inconsistent with the repo’s existing overture-pull-requester identity usage.

Once you've addressed the issues Copilot identified, you can request another Copilot review.

Pull request overview

This PR updates the scheduled uv.lock refresh workflow to open/update its dependency-refresh PRs using the overture-pull-requester GitHub App token rather than the default GITHUB_TOKEN, so the resulting PR can bypass the required linked-issue check and trigger CI normally.

Changes:

  • Add an actions/create-github-app-token step to mint an installation token for overture-pull-requester.
  • Use that token for peter-evans/create-pull-request PR creation/updates.
  • Reduce job-level GITHUB_TOKEN permissions and update the commit message sign-off identity.
File summaries
File Description
.github/workflows/uv-lock-refresh.yml Switch PR creation for lockfile refresh to use the overture-pull-requester app token and adjust permissions/metadata accordingly.
Review details

Suppressed comments (1)

.github/workflows/uv-lock-refresh.yml:45

  • The issue/PR description for #731 calls out passing the GitHub App token to both actions/checkout and create-pull-request. Here actions/checkout still uses the default GITHUB_TOKEN, which keeps the workflow partially dependent on job-level permissions and can defeat the goal of running entirely under the app identity. Passing the app token to checkout (even with persist-credentials: false) aligns with the stated fix and reduces coupling to GITHUB_TOKEN behavior.
      - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
        with:
          persist-credentials: false

  • Files reviewed: 1/1 changed files
  • Comments generated: 1
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .github/workflows/uv-lock-refresh.yml
…t.yaml

Signed-off-by: John McCall <john@overturemaps.org>
@lowlydba
John McCall (lowlydba) merged commit 99f056b into main Sep 11, 2026
27 checks passed
@lowlydba
John McCall (lowlydba) deleted the lowlydba-fix-ci-failure branch September 11, 2026 13:58

This branch was successfully deployed

1 active deployment
staging — dd384532 Deployed Sep 10, 2026 by lowlydba via Deploy #525
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug](Platform) uv-lock-refresh PRs stuck on required linked-issue check

4 participants