Skip to content

fix: keep Actions pull request creation enabled - #64

Merged
loadinglucian merged 1 commit into
mainfrom
fix/allow-actions-pr-creation
Aug 5, 2026
Merged

fix: keep Actions pull request creation enabled#64
loadinglucian merged 1 commit into
mainfrom
fix/allow-actions-pr-creation

Conversation

@loadinglucian

@loadinglucian loadinglucian commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

Summary

The watcher failed this morning (run 30987026534, issue #63) because it could not open its daily evidence-record PR: GitHub Actions is not permitted to create or approve pull requests.

Root cause: scripts/configure-github-autorelease sets the workflow-permissions flag can_approve_pull_request_reviews to false. Despite its name, that flag governs the combined GitHub setting "Allow GitHub Actions to create and approve pull requests", so re-running the configure script during the ruleset migration (#61) switched off PR creation for GITHUB_TOKEN in both repos. The watcher's evidence-record PRs and the mise-php consumer's readiness PRs both depend on it, as documented in docs/repository-settings.md ("Keep the default Actions token read-only while enabling automation PR creation").

Changes

  • scripts/configure-github-autorelease: set the flag to true with a comment explaining that it also governs PR creation. Approvals remain owner-only through the ruleset and protected controls, and runtime workflows never submit approving reviews.
  • docs/admin-state/php-bin-after.json: regenerated with scripts/snapshot-github-admin-state after restoring the live setting.

The live setting has already been restored on both repos; a companion PR updates the mise-php snapshot.

Summary by CodeRabbit

  • Chores
    • Updated automated workflow permissions to support pull request review approvals.
    • Existing approval restrictions remain unchanged.
    • Refreshed the associated administrative state metadata.

The workflow-permissions flag named can_approve_pull_request_reviews
governs the combined "create and approve pull requests" permission.
Setting it to false broke the watcher's daily evidence-record PR and
the mise-php consumer's readiness PRs after the configure script was
re-run during the ruleset migration. Approvals stay owner-only via the
ruleset and protected controls.
@coderabbitai

coderabbitai Bot commented Aug 5, 2026

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 0ca8f2a6-372b-4396-b248-06e745395369

📥 Commits

Reviewing files that changed from the base of the PR and between 5adef4c and 3c5d501.

📒 Files selected for processing (2)
  • docs/admin-state/php-bin-after.json
  • scripts/configure-github-autorelease

📝 Walkthrough

Walkthrough

The autorelease workflow now enables pull-request review approval. The admin-state snapshot records the updated permission, timestamp, and digest.

Changes

Autorelease permission update

Layer / File(s) Summary
Enable review approval and refresh snapshot
scripts/configure-github-autorelease, docs/admin-state/php-bin-after.json
The workflow configuration enables can_approve_pull_request_reviews. The admin-state snapshot records the same permission, a new timestamp, and a new digest.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related PRs

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly identifies the main change: preserving GitHub Actions pull request creation.
Description check ✅ Passed The description clearly explains the failure, root cause, changes, and affected workflows, but it omits the template's Verification and Security sections.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/allow-actions-pr-creation

Comment @coderabbitai help to get the list of available commands.

@loadinglucian
loadinglucian merged commit 166c505 into main Aug 5, 2026
5 checks passed
@loadinglucian
loadinglucian deleted the fix/allow-actions-pr-creation branch August 5, 2026 08:24
loadinglucian added a commit to Bigpixelrocket/mise-php that referenced this pull request Aug 5, 2026
## Summary

Companion to Bigpixelrocket/php-bin#64. The workflow-permissions flag
`can_approve_pull_request_reviews` governs the combined "create and
approve pull requests" GitHub setting, and the autorelease consumer's
readiness PRs require it. Re-running the configure script during the
ruleset migration switched it off in both repos, which broke php-bin's
watcher this morning and would have broken the next consumer run that
needed to write a readiness record.

## Changes

- `docs/admin-state/mise-php-after.json`: regenerated with php-bin's
`scripts/snapshot-github-admin-state` after restoring the live setting
on this repo.

The configure-script fix itself lives in php-bin, which owns that
script.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **Chores**
- Updated workflow permissions to support approving pull request
reviews.
- Refreshed administrative state records and associated metadata to
reflect the latest configuration.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant