From 6e4cb2387f989b84862255f7b2077f2bae2b07bf Mon Sep 17 00:00:00 2001 From: Jan Rose Date: Wed, 7 Oct 2026 16:12:16 +0200 Subject: [PATCH] release-prs: sync winget-pkgs fork before publishing to winget MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit komac's `update --submit` creates the winget PR branch in the eng-dev-ecosystem-bot fork pointing at upstream's HEAD commit. When the fork's default branch drifts far behind upstream, GitHub rejects the branch creation with a misleading "does not have the correct permissions to execute `CreateRef`" error (komac#1142) — it is not a token problem. The fork was kept current by pull[bot], which GitHub suspended globally on 2026-09-30. With no syncing the fork drifted thousands of commits behind over the following week and the v1.20.0 winget publish failed. Run `komac sync-fork` before `komac update --submit` so the fork's default branch is fast-forwarded to upstream first. It reuses the same KOMAC_FORK_OWNER / GITHUB_TOKEN env and no-ops when already current, removing the dependency on pull[bot]. Co-authored-by: Isaac --- .github/workflows/release-prs.yml | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/.github/workflows/release-prs.yml b/.github/workflows/release-prs.yml index c7f41dcb375..f42b9d07670 100644 --- a/.github/workflows/release-prs.yml +++ b/.github/workflows/release-prs.yml @@ -230,6 +230,16 @@ jobs: if: ${{ !inputs.dry_run }} run: echo "$RUNNER_TEMP/komac" >> $GITHUB_PATH + # komac creates the winget PR branch in the fork at upstream's HEAD commit; when + # the fork's default branch drifts far behind, GitHub rejects the branch creation + # with a misleading CreateRef permissions error. Fast-forward the fork first. + - name: Sync winget-pkgs fork with upstream + if: ${{ !inputs.dry_run }} + run: komac sync-fork + env: + KOMAC_FORK_OWNER: eng-dev-ecosystem-bot + GITHUB_TOKEN: ${{ secrets.ENG_DEV_ECOSYSTEM_BOT_TOKEN }} + - name: Publish to Winget if: ${{ !inputs.dry_run }} run: |