From 7a5285630374df8290278973b386c7f0e1eeeeff Mon Sep 17 00:00:00 2001 From: Jamie Holding Date: Tue, 8 Sep 2026 14:13:29 +0100 Subject: [PATCH] ci(drift): open the PR as a GitHub App so its checks actually run MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The drift job opened its PR with GITHUB_TOKEN. GitHub does not start workflow runs from GITHUB_TOKEN-raised events, so the required test (3.x) checks never reported and the PR was blocked on a report it could not receive. #19 has sat that way since 2026-09-02 while its body said 'regenerate: success'. Fixed by minting a short-lived installation token from the tpw-drift app and handing it to create-pull-request. The push then comes from the app's identity rather than GITHUB_TOKEN, pull_request fires normally, and CI reports. The app holds contents:write and pull_requests:write on two repos and nothing else — notably not workflows:write, so it cannot alter CI. workflow_dispatch was tried first and rejected on evidence. It is a documented exception to the no-runs rule and does start a run, but that run's check runs do not satisfy branch protection: on a test PR a dispatched run put three successful check runs with the exact required names on the head SHA and left it BLOCKED with an empty rollup, while a push-event run on the next commit cleared it at once. The create-an-issue steps keep GITHUB_TOKEN deliberately. They open issues on failure, an issue does not need to trigger anything, and there is no reason to widen the app's reach. Co-Authored-By: Claude Opus 5 (1M context) --- .github/workflows/spec-drift.yml | 18 ++++++++++++++++++ 1 file changed, 18 insertions(+) diff --git a/.github/workflows/spec-drift.yml b/.github/workflows/spec-drift.yml index d0f175f..56e22db 100644 --- a/.github/workflows/spec-drift.yml +++ b/.github/workflows/spec-drift.yml @@ -31,9 +31,27 @@ jobs: if: steps.regen.outcome == 'success' continue-on-error: true run: pytest tests/live -v + # The PR must not be opened with GITHUB_TOKEN. GitHub does not start + # workflow runs from GITHUB_TOKEN-raised events, so a PR opened that way + # never gets its required checks and can never be merged, however good + # the diff is. Both drift PRs sat blocked for days on exactly that. + # + # workflow_dispatch is documented as an exception to the no-runs rule and + # does start a run — but measured against a real PR, those check runs do + # not satisfy branch protection even on the right SHA under the right + # names. A push-event run does. So the push has to come from an identity + # that is not GITHUB_TOKEN, and this app is that identity. + - name: Mint an installation token for the drift bot + id: app-token + uses: actions/create-github-app-token@v2 + with: + app-id: ${{ secrets.DRIFT_APP_ID }} + private-key: ${{ secrets.DRIFT_APP_PRIVATE_KEY }} + - name: Open PR if models changed uses: peter-evans/create-pull-request@v8 with: + token: ${{ steps.app-token.outputs.token }} branch: bot/spec-drift commit-message: "chore: regenerate models from upstream spec" title: "Spec drift: regenerate models"