Repository navigation
chore: approve with the machine-user PAT when it exists - #13
Conversation
DOTBOT_GITHUB_USER_PAT now exists in this repo, so the review workflow should use
it rather than settling for a bot-identity approval:
github_approval_token: ${{ secrets.DOTBOT_GITHUB_USER_PAT || github.token }}
The machine-user PAT is preferred — the approval is attributed to a real user
(the token's user must not be the PR author, or GitHub rejects it), and
`github.token` remains the fallback so consumer repos without the secret still
get approvals (as github-actions[bot]).
Docs and the workflow assertion move to the combined expression; the commit
statuses stay on the workflow token so they do not depend on the PAT.
|
dotbot code review:
Prefers machine-user PAT with workflow-token fallback for approval, keeps statuses on github.token, with matching README and test updates. No correctness, security, or atomicity defect introduced. Tip: comment with "/dotbot address comments" to attempt automated fixes for unresolved review threads. reviewed by dotbot · meta/muse-spark-1.3 · medium |
|
dotbot code review:
The change consistently switches the approval token to prefer secrets.DOTBOT_GITHUB_USER_PAT with a github.token fallback across the workflow, README, and the test that pins the workflow content. The fallback expression is valid GitHub Actions syntax (missing secrets evaluate falsy), and the author-mismatch requirement is documented in the comments. Tip: comment with "/dotbot address comments" to attempt automated fixes for unresolved review threads. reviewed by dotbot · ~z-ai/glm-latest · medium |
dotCMS-Machine-User
left a comment
There was a problem hiding this comment.
✅ dotbot review: all reviewer models (meta/muse-spark-1.3, ~z-ai/glm-latest) agree — patch is correct.
approved automatically by dotbot
What
DOTBOT_GITHUB_USER_PATnow exists in this repo, so the review workflow can approve as the machine user instead of asgithub-actions[bot]:Why prefer the PAT:
dotCMS-Machine-User) rather than a bot identity.github-actions[bot]) — that path is what feat: DOTBOT_ACT_MODEL for the act model, plus the fixes that unblock dotbot approval #7 wired and what has been approving here since.Caveat carried into the comment and README: GitHub rejects an approval from the PR author, so the PAT's user must differ from whoever opened the PR (a warning, never a failed run, if it is misconfigured).
Commit statuses stay on
github.tokenso they don't depend on the PAT.Verification
uv run pytest -q→ 808 passed;pre-commit run --all-files→ Passed;actionlint→ cleandotCMS-Machine-Userinstead ofgithub-actions[bot]