diff --git a/.github/workflows/rebase-translations.yml b/.github/workflows/rebase-translations.yml index 25a9870..dc53a70 100644 --- a/.github/workflows/rebase-translations.yml +++ b/.github/workflows/rebase-translations.yml @@ -25,8 +25,13 @@ jobs: # Keep this in step with `isTranslationBranch` in the action's src/branch-naming.ts # — this `if` decides whether the job runs, that predicate decides which open PRs # it then rebases, so a prefix matching only one of them is a no-op run. + # The head-repo check is belt-and-braces: fork PRs never receive secrets, so + # the PAT is not exposed either way — but a merged fork PR whose branch happens + # to match a prefix would otherwise start this job with an empty token and fail + # red. Same-repo branches matching these prefixes only come from the tooling. if: > github.event.pull_request.merged == true && + github.event.pull_request.head.repo.full_name == github.repository && (startsWith(github.event.pull_request.head.ref, 'translation-sync-') || startsWith(github.event.pull_request.head.ref, 'resync/')) runs-on: ubuntu-latest @@ -46,4 +51,11 @@ jobs: with: mode: rebase anthropic-api-key: ${{ secrets.ANTHROPIC_API_KEY }} - github-token: ${{ secrets.GITHUB_TOKEN }} + # PAT rather than the default GITHUB_TOKEN, deliberately: commits pushed + # with GITHUB_TOKEN trigger no workflows (GitHub's recursion guard), so a + # rebased branch ends up with a run-less head — force-pushed re-translated + # content lands unreviewed, and with required checks a run-less head blocks + # merging. Validated both ways on the test harness, 2026-07-21: zero runs + # under GITHUB_TOKEN, review triggered under the PAT. + # See QuantEcon/action-translation#125. + github-token: ${{ secrets.QUANTECON_SERVICES_PAT }}