Let sync PRs approve their own builds

The upstream and rebuild syncs push with GITHUB_TOKEN, so GitHub holds
their build and test runs for approval. Their approve job only released
those runs once a maintainer had applied build-approved, and never ran
for the push that opened the PR, so every sync PR sat waiting.

The sync now labels its own PR build-approved, and the approve job runs
for created PRs as well as updated ones.
This commit is contained in:
Ryan Hughes committed 2026-10-06 20:32:42 -04:00
1 parent 71154a8fdc
commit 5fb29fe547
5 files changed
+37 -22

No files matched your search

+11 -6
View File
@@ -113,7 +113,11 @@ jobs:
are left untouched; check the workflow result for outstanding failures.
branch: ${{ steps.branch.outputs.branch }}
delete-branch: true
labels: automated
# The bot is trusted; build-approved lets the approve job below
# release GitHub's hold on its pushes without a maintainer.
labels: |
automated
build-approved
reviewers: ryanrhughes
- name: Notify Basecamp on failure
@@ -130,12 +134,13 @@ jobs:
# GitHub holds pull_request runs from a GITHUB_TOKEN push for approval and
# creates no pull_request_target run for it, so approve-pr.yml never sees
# the sync's own pushes. Once a maintainer has labelled the PR
# build-approved, release the held runs for the commit just pushed. A
# separate job, so the sync container's token never holds actions: write.
# the sync's own pushes. The sync labels its PR build-approved, so release
# the held runs for the commit just pushed, whether it opened the PR or
# updated it. A separate job, so the sync container's token never holds
# actions: write.
approve:
needs: sync
if: ${{ !cancelled() && needs.sync.outputs.operation == 'updated' }}
if: ${{ !cancelled() && (needs.sync.outputs.operation == 'created' || needs.sync.outputs.operation == 'updated') }}
runs-on: ubuntu-latest
timeout-minutes: 5
permissions:
@@ -146,7 +151,7 @@ jobs:
- uses: actions/checkout@v4
with:
persist-credentials: false
- name: Release held build and test runs if build-approved
- name: Release held build and test runs
uses: actions/github-script@v7
env:
NUMBER: ${{ needs.sync.outputs.number }}