Context
The open-release-pr.yml workflow can create or update the dev -> main release PR using GITHUB_TOKEN.
On PR #293, the release PR was created successfully, but required test-pr stayed in Expected — Waiting for status to be reported because GitHub does not trigger most downstream workflows from GITHUB_TOKEN-authored events. Closing and reopening the PR manually triggered the expected pull_request checks.
Goal
Make release PR creation/update report required checks without requiring a manual close/reopen workaround.
Desired Outcome
A maintainer can run open-release-pr.yml and get a release PR that satisfies branch protection checks normally.
Scope
- Review
.github/workflows/open-release-pr.yml.
- Decide whether to use a narrowly scoped maintainer PAT/GitHub App token for PR creation/update, or another safe approach that causes required PR checks to run.
- Preserve existing gates:
- exactly one open release-readiness issue
ready: true
risk_level: none
- current dev SHA in readiness issue
- security facts available
- final pending checks = 0
- no auto-merge
- no publish
- Keep dry-run behavior non-mutating.
- Keep permissions minimal.
Acceptance Criteria
open-release-pr.yml can create or update dev -> main release PRs in a way that causes required pull_request checks like test-pr to report.
- The workflow documents the token source and why it is needed.
- If a PAT/App token is used, normal repo operations still use
GITHUB_TOKEN where possible.
- No branch-mutating automation is added beyond opening/updating the release PR.
- No auto-merge or publish behavior is added.
- Validation includes a dry-run and a real run or a clearly justified equivalent smoke test.
Known Workaround
Manual close/reopen of the release PR triggers the required checks, but this should not be the durable release flow.
Refs #293.
Context
The
open-release-pr.ymlworkflow can create or update thedev -> mainrelease PR usingGITHUB_TOKEN.On PR #293, the release PR was created successfully, but required
test-prstayed inExpected — Waiting for status to be reportedbecause GitHub does not trigger most downstream workflows fromGITHUB_TOKEN-authored events. Closing and reopening the PR manually triggered the expectedpull_requestchecks.Goal
Make release PR creation/update report required checks without requiring a manual close/reopen workaround.
Desired Outcome
A maintainer can run
open-release-pr.ymland get a release PR that satisfies branch protection checks normally.Scope
.github/workflows/open-release-pr.yml.ready: truerisk_level: noneAcceptance Criteria
open-release-pr.ymlcan create or updatedev -> mainrelease PRs in a way that causes requiredpull_requestchecks liketest-prto report.GITHUB_TOKENwhere possible.Known Workaround
Manual close/reopen of the release PR triggers the required checks, but this should not be the durable release flow.
Refs #293.