Skip to content

ci: remove broken dependabot-to-issues workflow - #32

Merged
rjamul-elnora-ai merged 1 commit into
mainfrom
chore/remove-broken-dependabot-to-issues
Jul 16, 2026
Merged

ci: remove broken dependabot-to-issues workflow#32
rjamul-elnora-ai merged 1 commit into
mainfrom
chore/remove-broken-dependabot-to-issues

Conversation

@rjamul-elnora-ai

Copy link
Copy Markdown
Member

Fixes the daily 'Create Issues from Dependabot Alerts / All jobs have failed' notifications.

Cause: the workflow reads Dependabot alerts with secrets.DEPENDABOT_PAT, which was retired when we moved to the App-token model — so DEPENDABOT_TOKEN is empty and the run fails 401 Unauthorized in ~2s on every cron. (The built-in GITHUB_TOKEN can't read Dependabot alerts, which is why it needed a PAT.)

Why remove rather than re-token: it's the old 'alert → GitHub issue' pattern. elnora-plugins' dependency updates already flow through the centralized dep-batch-review, and the repo currently has 0 open Dependabot alerts (github-actions ecosystem only), so it has nothing to do.

The sibling codeql-to-issues.yml is left untouched — it uses the built-in GITHUB_TOKEN and is passing.

🤖 Generated with Claude Code

https://claude.ai/code/session_01WUhYjxo3aEXF4RZE1oRmtL

This workflow reads Dependabot alerts via the retired DEPENDABOT_PAT (built-in
GITHUB_TOKEN can't read Dependabot alerts), so it fails 401 on every daily run.
It's the old "alert → GitHub issue" pattern; elnora-plugins dependency updates
already flow through the centralized dep-batch-review, and there are no open
alerts. Remove it to stop the daily failure notifications.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WUhYjxo3aEXF4RZE1oRmtL
@rjamul-elnora-ai
rjamul-elnora-ai merged commit 559c0c1 into main Jul 16, 2026
5 checks passed
@rjamul-elnora-ai
rjamul-elnora-ai deleted the chore/remove-broken-dependabot-to-issues branch July 16, 2026 13:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant