Skip to content

[scanner] Automation PRs never run CI — GITHUB_TOKEN-created PRs don't trigger pull_request workflows, leaving PR #681 permanently blocked #715

Description

@hivecommons-hive

Finding

All three PR-creating automation workflows — import-architectures.yml, refresh-radar-reports.yml, and refresh-community-people.yml — call peter-evans/create-pull-request with no token: override, so the PR is created with the default GITHUB_TOKEN and authored by github-actions[bot].

GitHub deliberately does not trigger on: pull_request workflow runs for events caused by GITHUB_TOKEN (recursion prevention). The result: automation PRs never run ci.yml (Validate repository) or codeql.yml. The only check that appears is DCO, which is a GitHub App and unaffected.

Steps to Reproduce / Evidence

PR #681 (chore: import latest reference architectures, opened 2026-09-26T02:36Z by app/github-actions):

$ gh api repos/cncf/endusers/commits/automation/import-architectures/check-runs
DCO completed success        # <-- the ONLY check run on the head commit

$ gh pr view 681 --json mergeable,mergeStateStatus
mergeable=MERGEABLE  mergeStateStatus=BLOCKED

The PR sits permanently blocked: the required validation either never runs (unvalidated content can only be merged by overriding protections) or a maintainer must manually close/reopen or push to the branch to nudge CI. Either way the automation lane cannot self-serve as designed.

Workflow sources (main @ b54cf81):

  • .github/workflows/import-architectures.yml:43 — create-pull-request@v8.1.1, no token:
  • .github/workflows/refresh-radar-reports.yml:31 — same
  • .github/workflows/refresh-community-people.yml:29 — same
  • .github/workflows/ci.yml:3 — on: pull_request (never fires for these PRs)

Recommendation

Create the PR with a GitHub App token instead of GITHUB_TOKEN, per the peter-evans/create-pull-request docs — e.g. add an actions/create-github-app-token step and pass its output as token: to all three workflows. PRs authored by an App bot trigger pull_request workflows normally, so Validate repository runs and the automation lane becomes mergeable through the normal gate. One shared fix closes this for all three workflows.


Filed by scanner agent (ACMM L4 — issues-only mode)

🐝 Hive Agent: scanner | Instance: hosted-available-lke648397-260827-5n31 | SHA: unknown

— hive: agent=scanner backend=copilot model=kimi-k3 copilot=1.0.88

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    agent/scannerApproved by a Hive merger/owner for auto-merge on green CIbugSomething isn't workinghive/hosted-available-lke648397-260827-5n31Approved by a Hive merger/owner for auto-merge on green CI

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions