Skip to content

Fix Dependabot CI authentication - #6486

Closed
cwperks wants to merge 1 commit into
opensearch-project:mainfrom
cwperks:fix/dependabot-ci-auth
Closed

cwperks wants to merge 1 commit into
opensearch-project:mainfrom
cwperks:fix/dependabot-ci-auth

Conversation

@cwperks

@cwperks cwperks commented Sep 7, 2026

Copy link
Copy Markdown
Member

Description

Dependabot-triggered workflows do not receive Actions secrets. This caused:

  • report-coverage to upload without CODECOV_TOKEN, which Codecov rejected because the Dependabot branch is protected
  • Dependabot PR actions to fail immediately because APP_ID and APP_PRIVATE_KEY were unavailable

This change:

  • authenticates Codecov uploads with GitHub OIDC instead of a long-lived secret
  • removes the obsolete Dependabot helper workflow

The removed workflow no longer has effective responsibilities: changelog automation was removed, the skip-changelog label is no longer consumed, Spotless is covered by Code Hygiene, and updateShas is skipped because dependency license checks are disabled.

Validation

@github-actions

github-actions Bot commented Sep 7, 2026

Copy link
Copy Markdown
Contributor

PR Reviewer Guide 🔍

Here are some key observations to aid the review process:

🧪 No relevant tests
🔒 No security concerns identified
✅ No TODO sections
🔀 No multiple PR themes
⚡ No major issues detected

@cwperks cwperks closed this Sep 18, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant