fix(ci): use UPSTREAM_TOKEN for both checkout and sync push

GITHUB_TOKEN cannot push commits that contain changes to
.github/workflows/ files (GitHub security restriction).
Use a Classic PAT with 'repo' + 'workflow' scopes instead.

Also add explicit checkout with fetch-depth:0 and ref:master
so the Fork-Sync action has full history for merging.
This commit is contained in:
TonyBlu 2026-05-25 22:50:00 +08:00
parent e7f816a5bd
commit 0b66872d6b

View file

@ -16,7 +16,14 @@ jobs:
if: ${{ github.event.repository.fork }}
steps:
# Checkout with UPSTREAM_TOKEN (Classic PAT with repo + workflow scope)
# GITHUB_TOKEN cannot push commits that modify .github/workflows/ files
- uses: actions/checkout@v4
with:
ref: master
fetch-depth: 0
token: ${{ secrets.UPSTREAM_TOKEN }}
persist-credentials: true
- name: Clean issue notice
uses: actions-cool/issues-helper@e361abf610221f09495ad510cb1e69328d839e1c # v3.7.6
@ -31,7 +38,7 @@ jobs:
upstream_sync_repo: alexta69/metube
upstream_sync_branch: master
target_sync_branch: master
target_repo_token: ${{ secrets.GITHUB_TOKEN }} # automatically generated, no need to set
target_repo_token: ${{ secrets.UPSTREAM_TOKEN }}
test_mode: false
- name: Sync check