From 755dd46d45c474f0a5c1f2cd42c1ed0c094b5052 Mon Sep 17 00:00:00 2001 From: Julio Quinteros Pro Date: Thu, 19 Feb 2026 19:52:01 -0300 Subject: [PATCH 1/4] fix(ci): fall back to github.token when GH_TOKEN secret is not set When secrets.GH_TOKEN is not configured, the workflow fails immediately with: "Input required and not supplied: token" Using || github.token ensures a valid token is always available. GH_TOKEN (PAT) is preferred when set; github.token is used as fallback. Co-Authored-By: Claude Sonnet 4.6 --- .github/workflows/regenerate-poetry-lock.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/regenerate-poetry-lock.yml b/.github/workflows/regenerate-poetry-lock.yml index 17791f411cf..dac680e5342 100644 --- a/.github/workflows/regenerate-poetry-lock.yml +++ b/.github/workflows/regenerate-poetry-lock.yml @@ -20,7 +20,7 @@ jobs: steps: - uses: actions/checkout@v4 with: - token: ${{ secrets.GH_TOKEN }} + token: ${{ secrets.GH_TOKEN || github.token }} - name: Set up Python uses: actions/setup-python@v5 @@ -74,4 +74,4 @@ jobs: --head "$BRANCH" \ --base main env: - GH_TOKEN: ${{ secrets.GH_TOKEN }} + GH_TOKEN: ${{ secrets.GH_TOKEN || github.token }} From e5906740831de2c11b7a9bed5af775c17a40a928 Mon Sep 17 00:00:00 2001 From: Julio Quinteros Pro Date: Thu, 19 Feb 2026 19:55:33 -0300 Subject: [PATCH 2/4] fix(ci): use PAT_TOKEN_2 instead of non-existent GH_TOKEN secret GH_TOKEN is not configured in this repository. The correct PAT secret is PAT_TOKEN_2, which has the permissions needed to push branches and open PRs. Co-Authored-By: Claude Sonnet 4.6 --- .github/workflows/regenerate-poetry-lock.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/regenerate-poetry-lock.yml b/.github/workflows/regenerate-poetry-lock.yml index dac680e5342..723291cb000 100644 --- a/.github/workflows/regenerate-poetry-lock.yml +++ b/.github/workflows/regenerate-poetry-lock.yml @@ -20,7 +20,7 @@ jobs: steps: - uses: actions/checkout@v4 with: - token: ${{ secrets.GH_TOKEN || github.token }} + token: ${{ secrets.PAT_TOKEN_2 }} - name: Set up Python uses: actions/setup-python@v5 @@ -74,4 +74,4 @@ jobs: --head "$BRANCH" \ --base main env: - GH_TOKEN: ${{ secrets.GH_TOKEN || github.token }} + GH_TOKEN: ${{ secrets.PAT_TOKEN_2 }} From 8cc50d67369a5c2acb74acb338d4d870009f76b4 Mon Sep 17 00:00:00 2001 From: Julio Quinteros Pro Date: Thu, 19 Feb 2026 19:55:44 -0300 Subject: [PATCH 3/4] chore: fix stale GH_TOKEN comment --- .github/workflows/regenerate-poetry-lock.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/regenerate-poetry-lock.yml b/.github/workflows/regenerate-poetry-lock.yml index 723291cb000..7dd9a728a12 100644 --- a/.github/workflows/regenerate-poetry-lock.yml +++ b/.github/workflows/regenerate-poetry-lock.yml @@ -12,7 +12,7 @@ on: workflow_dispatch: permissions: - contents: read # GITHUB_TOKEN is not used for writes; GH_TOKEN (PAT) handles push + PR creation + contents: read # GITHUB_TOKEN is not used for writes; PAT_TOKEN_2 handles push + PR creation jobs: regenerate-lock: From 54470ec1d9c1270051713f6cc54cba4c9feb7f86 Mon Sep 17 00:00:00 2001 From: Julio Quinteros Pro Date: Thu, 19 Feb 2026 19:56:59 -0300 Subject: [PATCH 4/4] fix(ci): use github.token with explicit permissions instead of PAT secret MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Drop the PAT_TOKEN_2 secret (whose scope is unknown) in favour of the built-in github.token, which is always available. Grant it exactly the two permissions it needs: - contents: write → push the auto/regenerate-* branch - pull-requests: write → open the PR via gh cli No external secret needed. Co-Authored-By: Claude Sonnet 4.6 --- .github/workflows/regenerate-poetry-lock.yml | 7 +++---- 1 file changed, 3 insertions(+), 4 deletions(-) diff --git a/.github/workflows/regenerate-poetry-lock.yml b/.github/workflows/regenerate-poetry-lock.yml index 7dd9a728a12..8da2d70394d 100644 --- a/.github/workflows/regenerate-poetry-lock.yml +++ b/.github/workflows/regenerate-poetry-lock.yml @@ -12,15 +12,14 @@ on: workflow_dispatch: permissions: - contents: read # GITHUB_TOKEN is not used for writes; PAT_TOKEN_2 handles push + PR creation + contents: write # needed to push the auto/regenerate-poetry-lock-* branch + pull-requests: write # needed to open the PR jobs: regenerate-lock: runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - with: - token: ${{ secrets.PAT_TOKEN_2 }} - name: Set up Python uses: actions/setup-python@v5 @@ -74,4 +73,4 @@ jobs: --head "$BRANCH" \ --base main env: - GH_TOKEN: ${{ secrets.PAT_TOKEN_2 }} + GH_TOKEN: ${{ github.token }}