From 307600bf8b410c2178c487a225bf386d5c14a250 Mon Sep 17 00:00:00 2001 From: Phil Leggetter Date: Sun, 27 Sep 2026 14:47:49 +0100 Subject: [PATCH] ci: skip acceptance on Dependabot pull requests instead of failing them GitHub does not pass repository secrets to a workflow Dependabot triggers, so every acceptance slice on a Dependabot PR failed in seconds on an empty test key -- "HOOKDECK_CLI_TESTING_API_KEY ... must be set" -- whatever the dependency. #459, #374 and #361 all went red this way. A check that is always red teaches people to ignore red. The caller job in test-acceptance.yml now skips when github.actor is dependabot[bot], matching how test.yml already treats build-linux. Merging a bump pushes to main as the merger, so the post-merge run has secrets and runs in full; dispatching the workflow on the Dependabot branch tests it before merging. The release gate calls acceptance.yml directly and is unaffected. The review skill records that skipped is not covered, and what covers it. Co-Authored-By: Claude Opus 5.5 (1M context) Claude-Session: https://claude.ai/code/session_012XtSQ2kfpcRXXqweskgXkH --- .agents/skills/hookdeck-cli-review/SKILL.md | 12 ++++++++++++ .github/workflows/test-acceptance.yml | 11 +++++++++++ 2 files changed, 23 insertions(+) diff --git a/.agents/skills/hookdeck-cli-review/SKILL.md b/.agents/skills/hookdeck-cli-review/SKILL.md index bdefba28..b38449d2 100644 --- a/.agents/skills/hookdeck-cli-review/SKILL.md +++ b/.agents/skills/hookdeck-cli-review/SKILL.md @@ -66,6 +66,18 @@ than the colour: gh run view --job= --log | grep -E -- '--- (SKIP|PASS): ' ``` +### Dependabot pull requests skip acceptance, on purpose + +GitHub does not pass repository secrets to a workflow Dependabot triggers, so +acceptance on a Dependabot PR used to fail every slice in seconds on an empty +test key, whatever the bump. `test-acceptance.yml` now skips the job when +`github.actor` is `dependabot[bot]`, so the check reads skipped, not red. + +That is not the same as covered. The post-merge push to `main` runs as the +person who merged, with secrets, and is the real run -- confirm it finished. +For a bump that touches something tests exercise, check before merging: run the +related tags locally, or dispatch the workflow on the Dependabot branch. + ### A cancelled acceptance run is not a run either Every acceptance run shares one concurrency group, `acceptance-suite`, so runs diff --git a/.github/workflows/test-acceptance.yml b/.github/workflows/test-acceptance.yml index e5e54a62..dc90b31e 100644 --- a/.github/workflows/test-acceptance.yml +++ b/.github/workflows/test-acceptance.yml @@ -76,5 +76,16 @@ on: jobs: acceptance: + # Not for Dependabot. GitHub does not pass repository secrets to a workflow + # Dependabot triggers, so every test key is empty and every slice fails in + # seconds with "HOOKDECK_CLI_TESTING_API_KEY ... must be set" -- whatever the + # dependency. A check that is always red teaches people to ignore red, so + # it is skipped instead. + # + # A dependency bump is still covered: merging it pushes to main as the + # merger, not Dependabot, so the post-merge run has secrets and runs in full. + # To test before merging, dispatch this workflow on the Dependabot branch. + # The release gate calls acceptance.yml directly and is unaffected. + if: github.actor != 'dependabot[bot]' uses: ./.github/workflows/acceptance.yml secrets: inherit