ci(#660): use scoped GSD_BOT_PR_TOKEN for backmerge & release merge-back PR creation (#673)

The open-gsd org blocks the Actions GITHUB_TOKEN from creating PRs, so
auto-backmerge and the release finalize merge-back PR steps can't open
their PRs (must be done manually). Point those two steps at a scoped
secret (pull-requests:write + contents:write), falling back to
GITHUB_TOKEN so behavior is unchanged until the secret is added.

Refs #660

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
Tom Boucher
2026-06-04 09:15:58 -04:00
committed by GitHub
parent 7ebff4058e
commit e8dc420b4d
2 changed files with 3 additions and 3 deletions

View File

@@ -56,7 +56,7 @@ jobs:
if: steps.check.outputs.next_exists == 'true'
id: branch
env:
GH_TOKEN: ${{ github.token }}
GH_TOKEN: ${{ secrets.GSD_BOT_PR_TOKEN || secrets.GITHUB_TOKEN }}
run: |
set -euo pipefail
SHORT_SHA=$(git rev-parse --short HEAD)
@@ -108,7 +108,7 @@ jobs:
- name: Open or update PR
if: steps.check.outputs.next_exists == 'true' && steps.branch.outputs.reused != 'true'
env:
GH_TOKEN: ${{ github.token }}
GH_TOKEN: ${{ secrets.GSD_BOT_PR_TOKEN || secrets.GITHUB_TOKEN }}
BR: ${{ steps.branch.outputs.branch }}
run: |
set -euo pipefail

View File

@@ -326,7 +326,7 @@ jobs:
if: ${{ !inputs.dry_run }}
continue-on-error: true
env:
GH_TOKEN: ${{ github.token }}
GH_TOKEN: ${{ secrets.GSD_BOT_PR_TOKEN || secrets.GITHUB_TOKEN }}
BRANCH: ${{ needs.validate-version.outputs.branch }}
VERSION: ${{ inputs.version }}
run: |