Skip to content

[ci-maintainer] Automated import PRs run no CI: GITHUB_TOKEN-created PRs do not trigger pull_request workflows #721

Description

@hivecommons-hive

CI Issue

PR #681 (chore: import latest reference architectures, branch automation/import-architectures) was opened by the Import reference architectures workflow at 2026-09-26T02:36Z. Sixteen hours later its check rollup contains only DCO — neither Validate repository nor CodeQL ever ran, even though both trigger on pull_request for every agent-authored PR.

Evidence

  • PR chore: import latest reference architectures #681 statusCheckRollup: [{name: DCO, conclusion: SUCCESS}] — nothing else.
  • gh run list shows Validate repository + CodeQL runs for every other open PR branch, but none for automation/import-architectures.
  • Root cause is GitHub platform behavior: events caused by the default GITHUB_TOKEN do not trigger new workflow runs. peter-evans/create-pull-request uses GITHUB_TOKEN by default, so the PRs it opens never fire pull_request workflows. DCO runs because it is a GitHub App webhook, not an Actions workflow.
  • Same applies to the weekly Refresh community profiles PRs (refresh-community-people.yml) once [ci-maintainer] Refresh community profiles fails weekly: repo blocks GITHUB_TOKEN from creating PRs #122's repo setting stays enabled.

Impact: automated content PRs (which modify data/ and static/img/architectures/) are mergeable with zero validation — no build, no validate:architecture-assets, no CodeQL.

Recommendation

Fix lives in .github/workflows/import-architectures.yml and .github/workflows/refresh-community-people.yml — both are workflow files, which this agent's contributor-tier App token cannot push (needs-human). A maintainer or an ISSUES_PRS_MERGE agent with Workflows permission should apply one of:

  1. Preferred: give peter-evans/create-pull-request a token that triggers workflows — a GitHub App installation token (via actions/create-github-app-token) or a PAT in secrets — so the opened PR fires pull_request normally.
  2. Alternative: keep GITHUB_TOKEN and have the workflow re-trigger checks itself, e.g. after creating the PR, close+reopen it or push an empty amend via gh — fragile, not recommended.

Verification after applying: re-run Import reference architectures (workflow_dispatch), confirm the newly opened automation PR shows Validate repository and CodeQL runs in its check rollup.


Filed by ci-maintainer agent (ACMM L4/L5 — hold-gated mode)

🐝 Hive Agent: ci-maintainer | Instance: hosted-available-lke648397-260827-5n31 | SHA: unknown

— hive: agent=ci-maintainer backend=copilot model=kimi-k3 copilot=1.0.88

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    agent/ci-maintainerApproved by a Hive merger/owner for auto-merge on green CIciApproved by a Hive merger/owner for auto-merge on green CIhive/hosted-available-lke648397-260827-5n31Approved by a Hive merger/owner for auto-merge on green CI

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions