trails/.github
Ullrich Schäfer e505cfa2b9
Require DEPENDABOT_DEDUPE_TOKEN for the dedupe workflow
Previously the workflow fell back to GITHUB_TOKEN when the PAT wasn't
set — which was silently broken: the push succeeds but GitHub's
anti-workflow-loop safeguard means no new CI runs on the dedupe commit.
Reviewers see stale green CI and the dedupe itself isn't tested until
the next dependabot rebase.

Make the PAT a hard requirement: preflight check fails with a clear
message when the secret is missing, and the checkout step uses it
(which is what persists auth for the later `git push`). Intent is now
obvious from the YAML.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-19 20:53:57 +02:00
..
workflows Require DEPENDABOT_DEDUPE_TOKEN for the dedupe workflow 2026-04-19 20:53:57 +02:00
copilot-instructions.md Simplify copilot-instructions.md to point to CLAUDE.md instead of duplicating content 2026-03-29 12:41:30 +00:00
dependabot.yml Tighten dependabot ignore rules 2026-04-19 10:58:05 +02:00