Finding
All three PR-creating automation workflows — import-architectures.yml, refresh-radar-reports.yml, and refresh-community-people.yml — call peter-evans/create-pull-request with no token: override, so the PR is created with the default GITHUB_TOKEN and authored by github-actions[bot].
GitHub deliberately does not trigger on: pull_request workflow runs for events caused by GITHUB_TOKEN (recursion prevention). The result: automation PRs never run ci.yml (Validate repository) or codeql.yml. The only check that appears is DCO, which is a GitHub App and unaffected.
Steps to Reproduce / Evidence
PR #681 (chore: import latest reference architectures, opened 2026-09-26T02:36Z by app/github-actions):
$ gh api repos/cncf/endusers/commits/automation/import-architectures/check-runs
DCO completed success # <-- the ONLY check run on the head commit
$ gh pr view 681 --json mergeable,mergeStateStatus
mergeable=MERGEABLE mergeStateStatus=BLOCKED
The PR sits permanently blocked: the required validation either never runs (unvalidated content can only be merged by overriding protections) or a maintainer must manually close/reopen or push to the branch to nudge CI. Either way the automation lane cannot self-serve as designed.
Workflow sources (main @ b54cf81):
.github/workflows/import-architectures.yml:43 — create-pull-request@v8.1.1, no token:
.github/workflows/refresh-radar-reports.yml:31 — same
.github/workflows/refresh-community-people.yml:29 — same
.github/workflows/ci.yml:3 — on: pull_request (never fires for these PRs)
Recommendation
Create the PR with a GitHub App token instead of GITHUB_TOKEN, per the peter-evans/create-pull-request docs — e.g. add an actions/create-github-app-token step and pass its output as token: to all three workflows. PRs authored by an App bot trigger pull_request workflows normally, so Validate repository runs and the automation lane becomes mergeable through the normal gate. One shared fix closes this for all three workflows.
Filed by scanner agent (ACMM L4 — issues-only mode)
🐝 Hive Agent: scanner | Instance: hosted-available-lke648397-260827-5n31 | SHA: unknown
— hive: agent=scanner backend=copilot model=kimi-k3 copilot=1.0.88
Finding
All three PR-creating automation workflows —
import-architectures.yml,refresh-radar-reports.yml, andrefresh-community-people.yml— callpeter-evans/create-pull-requestwith notoken:override, so the PR is created with the defaultGITHUB_TOKENand authored bygithub-actions[bot].GitHub deliberately does not trigger
on: pull_requestworkflow runs for events caused byGITHUB_TOKEN(recursion prevention). The result: automation PRs never runci.yml(Validate repository) orcodeql.yml. The only check that appears is DCO, which is a GitHub App and unaffected.Steps to Reproduce / Evidence
PR #681 (
chore: import latest reference architectures, opened 2026-09-26T02:36Z byapp/github-actions):The PR sits permanently blocked: the required validation either never runs (unvalidated content can only be merged by overriding protections) or a maintainer must manually close/reopen or push to the branch to nudge CI. Either way the automation lane cannot self-serve as designed.
Workflow sources (main @ b54cf81):
.github/workflows/import-architectures.yml:43—create-pull-request@v8.1.1, notoken:.github/workflows/refresh-radar-reports.yml:31— same.github/workflows/refresh-community-people.yml:29— same.github/workflows/ci.yml:3—on: pull_request(never fires for these PRs)Recommendation
Create the PR with a GitHub App token instead of
GITHUB_TOKEN, per thepeter-evans/create-pull-requestdocs — e.g. add anactions/create-github-app-tokenstep and pass its output astoken:to all three workflows. PRs authored by an App bot triggerpull_requestworkflows normally, soValidate repositoryruns and the automation lane becomes mergeable through the normal gate. One shared fix closes this for all three workflows.Filed by scanner agent (ACMM L4 — issues-only mode)
🐝 Hive Agent:
scanner| Instance:hosted-available-lke648397-260827-5n31| SHA:unknown— hive: agent=scanner backend=copilot model=kimi-k3 copilot=1.0.88