From 83aeb29143acf5855a0d89ba6925169d3acb22fb Mon Sep 17 00:00:00 2001 From: Yauhen Bichel Date: Fri, 11 Sep 2026 12:16:27 +0100 Subject: [PATCH] Pass the wall its deploy key by name secrets: inherit only reaches a reusable workflow in the same organisation, and the wall lives under YauhenBichel, so it passed nothing. The wall fell back to the workflow token, which the protected main refuses: every run logged WITH_DEPLOY_KEY false, and the org profile's wall failed with GH013 on its first real push. The key is now passed explicitly. Co-Authored-By: Claude Opus 5 --- .github/workflows/contributors.yml | 10 ++++++++-- 1 file changed, 8 insertions(+), 2 deletions(-) diff --git a/.github/workflows/contributors.yml b/.github/workflows/contributors.yml index cf9b6e8..54eb5e0 100644 --- a/.github/workflows/contributors.yml +++ b/.github/workflows/contributors.yml @@ -12,7 +12,12 @@ name: Contributors # profile's wall stayed empty. # # main is protected, so the wall pushes through the write deploy key stored as -# CONTRIBUTORS_DEPLOY_KEY. `secrets: inherit` hands it over. +# CONTRIBUTORS_DEPLOY_KEY. +# +# The key is passed by name, not with `secrets: inherit`: inherit only reaches +# a reusable workflow in the same organisation, and the wall lives under +# YauhenBichel, so inherit passed nothing and the push fell back to the +# workflow token, which the protected branch refuses. on: push: @@ -30,4 +35,5 @@ jobs: with: readme: profile/README.md format: html - secrets: inherit + secrets: + CONTRIBUTORS_DEPLOY_KEY: ${{ secrets.CONTRIBUTORS_DEPLOY_KEY }}