diff --git a/.github/workflows/publish.yaml b/.github/workflows/publish.yaml index 3ae9300..b42d380 100644 --- a/.github/workflows/publish.yaml +++ b/.github/workflows/publish.yaml @@ -23,10 +23,13 @@ jobs: release_created: ${{ steps.release.outputs.release_created }} tag_name: ${{ steps.release.outputs.tag_name }} steps: + # A push made with GITHUB_TOKEN does not start any workflow, so a release + # PR merged with it lands on main and then nothing publishes. Using the + # PAT keeps the chain alive and also lets CI run on the release PR. - uses: googleapis/release-please-action@v4 id: release with: - token: ${{ secrets.GITHUB_TOKEN }} + token: ${{ secrets.SDK_SYNC_PAT }} release-type: python config-file: release-please-config.json manifest-file: .release-please-manifest.json @@ -38,7 +41,7 @@ jobs: # would wait forever. - name: Merge the release PR env: - GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} + GH_TOKEN: ${{ secrets.SDK_SYNC_PAT }} RELEASE_PR: ${{ steps.release.outputs.pr }} run: | # The action's own output is authoritative and immediate. Listing by