chore(local): reuse FORGEJO_TOKEN for the auto-patch push instead of a new secret

Push the auto/registry-patch-proposals branch over HTTPS with FORGEJO_TOKEN (the
same token already used for the PR API), so no separate write-scoped REPO_RW_TOKEN
secret is needed. Drop it from propose-patches.R, the pipeline, and the docs.
This commit is contained in:
Patrick Schratz 2026-07-15 14:37:27 +00:00
commit aac87045e8
No known key found for this signature in database
GPG key ID: 62050D5BC68AB6DC

View file

@ -6,8 +6,9 @@
# human reviews the PR. Novel source diffs / unknown signatures are never
# proposed. Global across platforms, so a single job -- no matrix.
#
# Needs a write token (REPO_RW_TOKEN) to push and FORGEJO_TOKEN to open the PR.
# Register the `auto-apply-patches` cron in the crow UI, or run manually:
# FORGEJO_TOKEN is used for both the branch push and opening the PR (no separate
# write-scoped secret needed). Register the `auto-apply-patches` cron in the crow
# UI, or run manually:
# woodpecker-cli pipeline create --var task=auto-apply-patches --branch=main 7
variables:
patch_limit:
@ -34,8 +35,6 @@ steps:
from_secret: PGPASS
REPO_RO_TOKEN:
from_secret: REPO_RO_TOKEN
REPO_RW_TOKEN:
from_secret: REPO_RW_TOKEN
FORGEJO_TOKEN:
from_secret: FORGEJO_TOKEN
GIT_USER: devxy-bot