ci: remove broken dependabot-to-issues workflow - #32
Merged
Conversation
This workflow reads Dependabot alerts via the retired DEPENDABOT_PAT (built-in GITHUB_TOKEN can't read Dependabot alerts), so it fails 401 on every daily run. It's the old "alert → GitHub issue" pattern; elnora-plugins dependency updates already flow through the centralized dep-batch-review, and there are no open alerts. Remove it to stop the daily failure notifications. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01WUhYjxo3aEXF4RZE1oRmtL
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes the daily 'Create Issues from Dependabot Alerts / All jobs have failed' notifications.
Cause: the workflow reads Dependabot alerts with
secrets.DEPENDABOT_PAT, which was retired when we moved to the App-token model — soDEPENDABOT_TOKENis empty and the run fails401 Unauthorizedin ~2s on every cron. (The built-inGITHUB_TOKENcan't read Dependabot alerts, which is why it needed a PAT.)Why remove rather than re-token: it's the old 'alert → GitHub issue' pattern. elnora-plugins' dependency updates already flow through the centralized
dep-batch-review, and the repo currently has 0 open Dependabot alerts (github-actions ecosystem only), so it has nothing to do.The sibling
codeql-to-issues.ymlis left untouched — it uses the built-inGITHUB_TOKENand is passing.🤖 Generated with Claude Code
https://claude.ai/code/session_01WUhYjxo3aEXF4RZE1oRmtL