Skip to content

Commit f4b2d0d

Browse files
authored
Merge pull request #83 from jablko/patch-1
Default github-token
2 parents a30bbbb + 26e18ca commit f4b2d0d

File tree

3 files changed

+3
-11
lines changed

3 files changed

+3
-11
lines changed

.github/workflows/dependabot-auto-merge.yml

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -14,8 +14,6 @@ jobs:
1414
- name: Fetch metadata
1515
id: metadata
1616
uses: ./
17-
with:
18-
github-token: "${{ secrets.GITHUB_TOKEN }}"
1917

2018
- name: Auto-merge
2119
run: gh pr merge --auto --merge "$PR_URL"

README.md

Lines changed: 2 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -24,14 +24,14 @@ jobs:
2424
id: dependabot-metadata
2525
uses: dependabot/[email protected]
2626
with:
27-
github-token: "${{ secrets.GITHUB_TOKEN }}"
2827
alert-lookup: true
2928
```
3029
3130
Supported inputs are:
3231
33-
- `github-token` (REQUIRED string)
32+
- `github-token` (string)
3433
- The `GITHUB_TOKEN` secret
34+
- Defaults to `${{ github.token }}`
3535
- `alert-lookup` (boolean)
3636
- If `true`, then call populate the `alert-state`, `ghsa-id` and `cvss` outputs.
3737
- Defaults to `false`
@@ -88,8 +88,6 @@ jobs:
8888
- name: Dependabot metadata
8989
id: dependabot-metadata
9090
uses: dependabot/[email protected]
91-
with:
92-
github-token: "${{ secrets.GITHUB_TOKEN }}"
9391
- name: Approve a PR
9492
run: gh pr review --approve "$PR_URL"
9593
env:
@@ -118,8 +116,6 @@ jobs:
118116
- name: Dependabot metadata
119117
id: dependabot-metadata
120118
uses: dependabot/[email protected]
121-
with:
122-
github-token: "${{ secrets.GITHUB_TOKEN }}"
123119
- name: Enable auto-merge for Dependabot PRs
124120
if: ${{contains(steps.dependabot-metadata.outputs.dependency-names, 'rails') && steps.dependabot-metadata.outputs.update-type == 'version-update:semver-patch'}}
125121
run: gh pr merge --auto --merge "$PR_URL"
@@ -149,8 +145,6 @@ jobs:
149145
- name: Dependabot metadata
150146
id: dependabot-metadata
151147
uses: dependabot/[email protected]
152-
with:
153-
github-token: "${{ secrets.GITHUB_TOKEN }}"
154148
- name: Add a label for all production dependencies
155149
if: ${{ steps.dependabot-metadata.outputs.dependency-type == 'direct:production' }}
156150
run: gh pr edit "$PR_URL" --add-label "production"

action.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,7 @@ inputs:
99
description: 'If true, then call populate the `alert-state`, `ghsa-id` and `cvss` outputs'
1010
github-token:
1111
description: 'The GITHUB_TOKEN secret'
12-
required: true
12+
default: ${{ github.token }}
1313
outputs:
1414
dependency-names:
1515
description: 'A comma-separated list of all package names updated.'

0 commit comments

Comments
 (0)