From 5de57269c74c6841dc7dce235faa7ab522e633cc Mon Sep 17 00:00:00 2001 From: Matt McKay Date: Tue, 21 Jul 2026 16:01:07 +1000 Subject: [PATCH] Rebase pushes with the machine-user PAT (action-translation#125) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Commits pushed with the default GITHUB_TOKEN trigger no workflows, so a rebased branch gets a run-less head: force-pushed re-translated content lands unreviewed, and with required checks a run-less head blocks merging. Measured both ways on the test harness 2026-07-21 — zero runs under GITHUB_TOKEN, review triggered under the PAT. Sync mode has always passed the PAT for exactly this reason; rebase pushing to the same PRs with a weaker token was an inconsistency, not a decision. Co-Authored-By: Claude Opus 4.8 (1M context) --- .github/workflows/rebase-translations.yml | 13 ++++++++++--- 1 file changed, 10 insertions(+), 3 deletions(-) diff --git a/.github/workflows/rebase-translations.yml b/.github/workflows/rebase-translations.yml index 40799f6..b108906 100644 --- a/.github/workflows/rebase-translations.yml +++ b/.github/workflows/rebase-translations.yml @@ -4,7 +4,7 @@ # When a translation PR is merged, this workflow automatically rebases the # other open translation PRs against the updated main branch. It covers both # kinds this tool creates: `translation-sync-*` branches from the Action's sync -# mode, and `resync/*` branches from the CLI's `forward --github`. +# mode, and `resync/*` branches from the CLI's `translate forward --github`. # # This eliminates merge conflicts caused by multiple upstream PRs # modifying the same files. See: https://github.com/QuantEcon/action-translation/issues/63 @@ -20,7 +20,7 @@ on: jobs: rebase: # Only run when a translation PR is merged. Both prefixes must be listed: - # sync mode creates `translation-sync-*`, while the CLI's `forward --github` + # sync mode creates `translation-sync-*`, while the CLI's `translate forward --github` # creates `resync/*`, and a wave of resync PRs goes stale the same way. # Keep this in step with `isTranslationBranch` in the action's src/branch-naming.ts # — this `if` decides whether the job runs, that predicate decides which open PRs @@ -46,4 +46,11 @@ jobs: with: mode: rebase anthropic-api-key: ${{ secrets.ANTHROPIC_API_KEY }} - github-token: ${{ secrets.GITHUB_TOKEN }} + # PAT rather than the default GITHUB_TOKEN, deliberately: commits pushed + # with GITHUB_TOKEN trigger no workflows (GitHub's recursion guard), so a + # rebased branch ends up with a run-less head — force-pushed re-translated + # content lands unreviewed, and with required checks a run-less head blocks + # merging. Validated both ways on the test harness, 2026-07-21: zero runs + # under GITHUB_TOKEN, review triggered under the PAT. + # See QuantEcon/action-translation#125. + github-token: ${{ secrets.QUANTECON_SERVICES_PAT }}