Skip to content

chore: move UPSTREAM_TAG out of build.yml into plain file - #2

Merged
saubhikdattagithub merged 2 commits into
mainfrom
fix/move-upstream-tag-to-file
Sep 28, 2026
Merged

saubhikdattagithub merged 2 commits into
mainfrom
fix/move-upstream-tag-to-file

Conversation

@saubhikdattagithub

@saubhikdattagithub saubhikdattagithub commented Sep 28, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • GITHUB_TOKEN cannot push changes to workflow files (.github/workflows/) without the workflows permission — causing the daily update-upstream-tag job to fail with "refusing to allow a GitHub App to create or update workflow without workflows permission"
  • Moves UPSTREAM_TAG from the env: block in build.yml into a plain UPSTREAM_TAG file at the repo root — same pattern used by gardenlinux/package-linux (prepare_source)
  • build.yml reads the tag via cat UPSTREAM_TAG after checkout
  • update_upstream.yml now writes to UPSTREAM_TAG instead of build.yml — no workflows permission needed

@saubhikdattagithub saubhikdattagithub self-assigned this Sep 28, 2026
GITHUB_TOKEN cannot push changes to workflow files without the
`workflows` permission, causing the daily update-upstream-tag job
to fail. Moving UPSTREAM_TAG into a plain UPSTREAM_TAG file (same
pattern as package-linux/prepare_source) means the auto-update
workflow only touches a plain file — no special permission needed.

build.yml reads the tag via `cat UPSTREAM_TAG` after checkout.
update_upstream.yml writes to UPSTREAM_TAG instead of build.yml.

Signed-off-by: Saubhik Datta <50126327+saubhikdattagithub@users.noreply.github.com>
Signed-off-by: Saubhik Datta <50126327+saubhikdattagithub@users.noreply.github.com>
@saubhikdattagithub
saubhikdattagithub force-pushed the fix/move-upstream-tag-to-file branch from abab181 to 63de91d Compare September 28, 2026 09:22
@saubhikdattagithub
saubhikdattagithub marked this pull request as ready for review September 28, 2026 09:23
@saubhikdattagithub
saubhikdattagithub merged commit 022250c into main Sep 28, 2026
1 of 3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant