Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Dependabot auto merge does not respect permissions. #268

Closed
rbowensv-contrast opened this issue Sep 28, 2022 · 1 comment
Closed

Dependabot auto merge does not respect permissions. #268

rbowensv-contrast opened this issue Sep 28, 2022 · 1 comment
Labels
bug Something isn't working

Comments

@rbowensv-contrast
Copy link

My team is trying to set up dependabot auto merge. We have auto approve working using the github token and granted PR write permissions but the same does not work for auto merge. Is there a way to get auto merge working without a PAT? Setting up a PAT for each repo in our Org isn't feasible.

@rbowensv-contrast rbowensv-contrast added the bug Something isn't working label Sep 28, 2022
@jeffwidman
Copy link
Member

jeffwidman commented Apr 7, 2023

This question isn't really about fetch-metadata, but rather the overall Dependabot tokens, and the current behavior is already explained in detail here:

Is there a way to get auto merge working without a PAT?

For now, you need a PAT.

Setting up a PAT for each repo in our Org isn't feasible.

Yeah, that's painful. I don't think there's currently a way to set an org-level PAT, but I'm not fully sure TBH. I suggest open a discussion in https://github.com/orgs/community/discussions/categories/code-security

@jeffwidman jeffwidman closed this as not planned Won't fix, can't repro, duplicate, stale Apr 7, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

2 participants