From 82b4a2a4410bd17187298d4756f651cc3d0513e8 Mon Sep 17 00:00:00 2001 From: Shinrai Date: Wed, 2 Sep 2026 21:18:49 -0700 Subject: [PATCH] ci(hotfix-redirector): map CLDMV_BOT_* GPG secrets so redirected security PRs are signed The dependabot-security redirect path in workflow-hotfix-redirector.yml@v4 cherry-picks onto `hotfixes` and needs the bot GPG key to sign the commit, or the redirected PR is silently blocked by required-signatures. wire the CLDMV_BOT_* signing secrets into the caller. See CLDMV/.github#257. --- .github/workflows/hotfix-redirector.yml | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/.github/workflows/hotfix-redirector.yml b/.github/workflows/hotfix-redirector.yml index 830cad6..9ff0443 100644 --- a/.github/workflows/hotfix-redirector.yml +++ b/.github/workflows/hotfix-redirector.yml @@ -49,3 +49,7 @@ jobs: # Map your repo/org secrets to the expected names. BOT_APP_CLIENT_ID: ${{ secrets.CLDMV_BOT_APP_CLIENT_ID }} BOT_APP_PRIVATE_KEY: ${{ secrets.CLDMV_BOT_APP_PRIVATE_KEY }} + BOT_NAME: ${{ secrets.CLDMV_BOT_NAME }} + BOT_EMAIL: ${{ secrets.CLDMV_BOT_EMAIL }} + BOT_GPG_PRIVATE_KEY: ${{ secrets.CLDMV_BOT_GPG_PRIVATE_KEY }} + BOT_GPG_PASSPHRASE: ${{ secrets.CLDMV_BOT_GPG_PASSPHRASE }}