[BUG](ci) Pin uv-lock-refresh commit author to overture-pull-requester - #741
Merged
Merged
Conversation
create-pull-request's author input defaults to github.actor (the triggering user) when unset, not the app token's identity. That mismatched the Signed-off-by trailer and failed DCO on PR #739 (triggered manually via workflow_dispatch). Pin author/committer to the app so this doesn't vary by trigger actor. Fixes #740 Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Signed-off-by: John McCall <john@overturemaps.org>
Contributor
There was a problem hiding this comment.
🟢 Approval recommended
No unresolved review comments; the workflow identity matches the DCO signoff.
Pull request overview
Updates the uv lock refresh workflow to keep generated commit metadata aligned with the DCO signoff.
Changes:
- Pins the commit author and committer to the
overture-pull-requesterbot. - Prevents trigger-dependent author/signoff mismatches.
File summaries
| File | Summary |
|---|---|
.github/workflows/uv-lock-refresh.yml |
Pins the bot identity for generated commits. |
Review details
- Files reviewed: 1/1 changed files
- Comments generated: 0
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
🗺️ Schema reference docs preview is live!
Note ♻️ This preview updates automatically with each push to this PR. |
John McCall (lowlydba)
requested review from
Seth Fitzsimmons (sethfitz) and
Victor Schappert (vcschapp)
September 11, 2026 14:37
Seth Fitzsimmons (sethfitz)
approved these changes
Sep 11, 2026
Alex Iannicelli (atiannicelli)
approved these changes
Sep 11, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Pins
author:andcommitter:on thecreate-pull-requeststep inuv-lock-refresh.ymltooverture-pull-requester[bot] <overture-pull-requester[bot]@users.noreply.github.com>.Why
#732 fixed the required linked-issue check by opening PRs as the
overture-pull-requesterapp, butcreate-pull-request'sauthorinput defaults togithub.actor(the triggering user) when not set explicitly — not the app token's identity. That mismatched theSigned-off-bytrailer and failed DCO on the follow-up PR (#739, triggered via manualworkflow_dispatch). Pinning both inputs keeps the commit author consistent with the signoff regardless of who/what triggers the run.Fixes #740
Testing
zizmor .github/workflows/uv-lock-refresh.yml— no findings.yaml.safe_load.workflow_dispatchrun.