Skip to content

ci: skip acceptance on Dependabot pull requests instead of failing them - #462

Merged
leggetter merged 1 commit into
mainfrom
ci/skip-acceptance-for-dependabot
Sep 27, 2026
Merged

leggetter merged 1 commit into
mainfrom
ci/skip-acceptance-for-dependabot

Conversation

@leggetter

Copy link
Copy Markdown
Collaborator

GitHub does not pass repository secrets to a workflow Dependabot triggers. Acceptance on every Dependabot PR therefore failed every slice in seconds on an empty test key — HOOKDECK_CLI_TESTING_API_KEY … must be set — whatever the dependency. #459, #374 and #361 all went red this way.

A check that is always red teaches people to ignore red.

Change

  • test-acceptance.yml: the caller job skips when github.actor is dependabot[bot] — the same condition test.yml already uses for build-linux.
  • The review skill records that skipped is not covered, and what covers it.

What still covers a dependency bump

  • The post-merge run on main — merging pushes as the person who merged, so it has secrets and runs in full.
  • Before merging, when a bump touches something tests exercise: run the related tags locally, or dispatch this workflow on the Dependabot branch (a dispatch runs as you, with secrets). chore(deps): Bump github.com/creack/pty from 1.1.17 to 1.1.24 #459 was checked the first way — the three pty tests, locally.
  • The release gate calls acceptance.yml directly and is unaffected.

Verified

  • YAML parses; the condition is on the job that calls the reusable workflow.
  • This PR changes a workflow, so it triggers acceptance itself — as a human actor, which exercises the not-skipped branch. The skipped branch is exercised by the next Dependabot PR.

🤖 Generated with Claude Code

https://claude.ai/code/session_012XtSQ2kfpcRXXqweskgXkH

GitHub does not pass repository secrets to a workflow Dependabot triggers, so
every acceptance slice on a Dependabot PR failed in seconds on an empty test key
-- "HOOKDECK_CLI_TESTING_API_KEY ... must be set" -- whatever the dependency.
#459, #374 and #361 all went red this way. A check that is always red teaches
people to ignore red.

The caller job in test-acceptance.yml now skips when github.actor is
dependabot[bot], matching how test.yml already treats build-linux. Merging a
bump pushes to main as the merger, so the post-merge run has secrets and runs in
full; dispatching the workflow on the Dependabot branch tests it before merging.
The release gate calls acceptance.yml directly and is unaffected.

The review skill records that skipped is not covered, and what covers it.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012XtSQ2kfpcRXXqweskgXkH
@leggetter
leggetter merged commit d469ee0 into main Sep 27, 2026
14 checks passed
@leggetter
leggetter deleted the ci/skip-acceptance-for-dependabot branch September 27, 2026 14:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant