Skip to content

fix(ci): stop asking Dependabot's runs to draft a changelog - #37

Merged
anthturner merged 1 commit into
developfrom
fix/changelog-skips-dependabot
Sep 22, 2026
Merged

anthturner merged 1 commit into
developfrom
fix/changelog-skips-dependabot

Conversation

@anthturner

Copy link
Copy Markdown
Owner

Summary

write the entry and push it onto the branch has failed on every Dependabot pull request since allowed_bots: claude landed — #31 and #33 are both carrying the red X right now:

Action failed with error: Workflow initiated by non-human actor: dependabot (type: Bot).
Add bot to allowed_bots list or use '*' to allow all bots.

Adding dependabot to allowed_bots would not fix it. GitHub hands a Dependabot-triggered pull_request run a read-only GITHUB_TOKEN and withholds repository secrets, so ANTHROPIC_API_KEY/CLAUDE_CODE_OAUTH_TOKEN arrive empty and the git push at the end of the job would 403. The failure would just move one step later. The job cannot succeed on those runs.

Since a dependency bump owes no changelog entry in the first place — docs/contributing/changelog.md scopes entries to user-facing change — the fix is to not start the job at all.

What changed

  • .github/workflows/changelog.yml: the mode job's if: now turns Dependabot away alongside the fork exclusion it already carried. A skipped mode skips write with it, so Dependabot pull requests show no changelog job rather than a failing one.
  • docs/contributing/changelog.md: the "How an Entry Gets Written" section now states the fork and Dependabot exclusions, which it previously did not mention at all.

Human pull requests are unaffected, and so is the Claude app's own drafting that #29 deliberately enabled — allowed_bots: claude stays as-is.

Test plan

  • python workspace.py check --only=docs-check — 3/3 steps pass
  • .github/workflows/changelog.yml parses; mode.if and write.if resolve as intended
  • Confirmed on the next Dependabot pull request: the changelog job should be absent, not red

🤖 Generated with Claude Code

Every Dependabot pull request has been failing `write the entry and push
it onto the branch` since the job started gating on `allowed_bots`. The
red X is not the real problem: GitHub hands a Dependabot-triggered run a
read-only GITHUB_TOKEN and withholds repository secrets, so adding the
bot to the allowlist would only move the failure from the actor check to
an unreachable model and a 403 on the push. The job cannot succeed on
those runs at all.

A dependency bump owes no entry either, so the fix is to not start:
`mode` now turns Dependabot away beside forks, and a skipped `mode`
skips `write` with it. Human pull requests are untouched, and so is the
Claude app's own drafting that #29 enabled.
@anthturner
anthturner merged commit 13b9e65 into develop Sep 22, 2026
10 checks passed
@anthturner
anthturner deleted the fix/changelog-skips-dependabot branch September 22, 2026 16:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant