Skip to content

Updated workflow to use PAT token #9

Updated workflow to use PAT token

Updated workflow to use PAT token #9

name: Sync Roadmap Status

Check warning on line 1 in .github/workflows/sync_roadmap_status.yml

View workflow run for this annotation

GitHub Actions / Sync Roadmap Status

Workflow execution policy warning (evaluate mode)

On November 2, 2026, GitHub will restrict `pull_request_target` on public repositories by default. To continue allowing the event trigger, configure an Actions policy. Learn more: https://gh.io/securely-using-pull_request_target#default-policy-for-pull_request_target
on:
issues:
types: [assigned, unassigned, closed, reopened]
# pull_request_target (not pull_request) so the workflow gets write
# access even for PRs opened from forks. Safe here because we never
# check out or run the fork's code — we only read the PR body
# (already in the event payload) and write to ROADMAP.md on main.
pull_request_target:
types: [opened, ready_for_review, closed]
# Run reconcile.py on demand ("Run workflow" button) and once a day
# as a safety net against any missed event (e.g. an issue closed
# before its ROADMAP.md line had "— #N" linked to it yet).
workflow_dispatch: {}
schedule:
- cron: "0 4 * * *"
permissions:
contents: write
jobs:
sync:
if: github.event_name == 'issues' || github.event_name == 'pull_request_target'
runs-on: ubuntu-latest
steps:
# Uses a PAT (not the default GITHUB_TOKEN) so the later push is
# attributed to an account the ruleset's bypass list actually
# recognizes. The default token authenticates as github-actions[bot],
# which doesn't hold a real repo "Write" role, so role-based bypass
# entries never apply to it no matter how they're configured.
- uses: actions/checkout@v4
with:
ref: main
token: ${{ secrets.ROADMAP_PAT }}
- uses: actions/setup-python@v5
with:
python-version: "3.12"
- name: Update ROADMAP.md
id: update
run: python scripts/roadmap/sync_roadmap.py
env:
GITHUB_EVENT_NAME: ${{ github.event_name }}
GITHUB_EVENT_PATH: ${{ github.event_path }}
- name: Commit ROADMAP.md
if: steps.update.outputs.changed == 'true'
uses: stefanzweifel/git-auto-commit-action@v5
with:
commit_message: "chore: sync roadmap status [skip ci]"
file_pattern: ROADMAP.md
- name: Sync Discord
if: steps.update.outputs.changed == 'true'
run: python scripts/roadmap/sync_discord.py
env:
DISCORD_WEBHOOK_URL: ${{ secrets.DISCORD_WEBHOOK_URL }}
DISCORD_MESSAGE_IDS: ${{ vars.DISCORD_MESSAGE_IDS }}
reconcile:
if: github.event_name == 'workflow_dispatch' || github.event_name == 'schedule'
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
with:
ref: main
token: ${{ secrets.ROADMAP_PAT }}
- uses: actions/setup-python@v5
with:
python-version: "3.12"
- name: Reconcile ROADMAP.md with issue states
id: update
run: python scripts/roadmap/reconcile_roadmap.py
env:
GITHUB_REPOSITORY: ${{ github.repository }}
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
- name: Commit ROADMAP.md
if: steps.update.outputs.changed == 'true'
uses: stefanzweifel/git-auto-commit-action@v5
with:
commit_message: "chore: reconcile roadmap status [skip ci]"
file_pattern: ROADMAP.md
- name: Sync Discord
if: steps.update.outputs.changed == 'true'
run: python scripts/roadmap/sync_discord.py
env:
DISCORD_WEBHOOK_URL: ${{ secrets.DISCORD_WEBHOOK_URL }}
DISCORD_MESSAGE_IDS: ${{ vars.DISCORD_MESSAGE_IDS }}