diff --git a/.github/workflows/codex-pr-review.yml b/.github/workflows/codex-pr-review.yml index 354e8a60ca..55036776c6 100644 --- a/.github/workflows/codex-pr-review.yml +++ b/.github/workflows/codex-pr-review.yml @@ -40,11 +40,14 @@ jobs: # an author_association gate: the pull_request webhook payload reports private org # members as CONTRIBUTOR/NONE (only public members show as MEMBER), which silently # skips auto-review for every private member. + # Dependabot-triggered runs get a separate secret scope, so this job has no API + # key and cannot review. workflow_call stays open for an explicit request. if: | github.event_name == 'workflow_call' || ( github.event.pull_request.draft == false && - github.event.pull_request.head.repo.fork == false + github.event.pull_request.head.repo.fork == false && + github.event.pull_request.user.login != 'dependabot[bot]' ) permissions: contents: read diff --git a/.github/workflows/discord-notification.yml b/.github/workflows/discord-notification.yml index d731faafd9..c83cbc90d3 100644 --- a/.github/workflows/discord-notification.yml +++ b/.github/workflows/discord-notification.yml @@ -13,7 +13,8 @@ on: jobs: notify_discord_when_pr_opened: - if: (github.event.pull_request.draft == false) && (github.event.action == 'opened' || github.event.action == 'ready_for_review') + # No thread is opened for Dependabot PRs, so nothing downstream may assume one. + if: (github.event.pull_request.draft == false) && (github.event.action == 'opened' || github.event.action == 'ready_for_review') && (github.event.pull_request.user.login != 'dependabot[bot]') uses: ./.github/workflows/shareable-discord-notification.yml with: PR_TITLE: ${{ github.event.pull_request.title }} @@ -28,7 +29,8 @@ jobs: DISCORD_BOT_TOKEN: ${{ secrets.DISCORD_AI_BOT_TOKEN }} merge_success_emoji: - if: github.event.action == 'closed' + # Must match open_thread's exclusion: this reacts to a thread that was never created. + if: github.event.action == 'closed' && github.event.pull_request.user.login != 'dependabot[bot]' uses: ./.github/workflows/shareable-discord-notification.yml with: PR_STATUS: "merged" diff --git a/.github/workflows/pi-pr-review.yml b/.github/workflows/pi-pr-review.yml index a89275cfb5..a18dc28ff2 100644 --- a/.github/workflows/pi-pr-review.yml +++ b/.github/workflows/pi-pr-review.yml @@ -38,11 +38,14 @@ jobs: # an author_association gate: the pull_request webhook payload reports private org # members as CONTRIBUTOR/NONE (only public members show as MEMBER), which silently # skips auto-review for every private member. + # Dependabot-triggered runs get a separate secret scope, so this job has no API + # key and cannot review. workflow_call stays open for an explicit request. if: | github.event_name == 'workflow_call' || ( github.event.pull_request.draft == false && - github.event.pull_request.head.repo.fork == false + github.event.pull_request.head.repo.fork == false && + github.event.pull_request.user.login != 'dependabot[bot]' ) permissions: contents: read diff --git a/.github/workflows/pr-ready-review.yml b/.github/workflows/pr-ready-review.yml index 4bfb5b4147..5e5c6a8c61 100644 --- a/.github/workflows/pr-ready-review.yml +++ b/.github/workflows/pr-ready-review.yml @@ -37,11 +37,14 @@ jobs: # an author_association gate: the pull_request webhook payload reports private org # members as CONTRIBUTOR/NONE (only public members show as MEMBER), which silently # skips auto-review for every private member. + # Dependabot-triggered runs get a separate secret scope, so this job has no API + # key and cannot review. workflow_call stays open for an explicit request. if: | github.event_name == 'workflow_call' || ( (github.event.pull_request.draft == false || github.event.pull_request.ready_for_review == true) && - github.event.pull_request.head.repo.fork == false + github.event.pull_request.head.repo.fork == false && + github.event.pull_request.user.login != 'dependabot[bot]' ) permissions: contents: read