Skip to content

ci: remove pull_request_review trigger from multi-approvers workflow - #804

Merged
hessjcg merged 1 commit into
mainfrom
ci-fix-multi-approvers
Oct 8, 2026
Merged

hessjcg merged 1 commit into
mainfrom
ci-fix-multi-approvers

Conversation

@hessjcg

@hessjcg hessjcg commented Oct 8, 2026

Copy link
Copy Markdown
Member

This change removes the pull_request_review trigger from .github/workflows/multi-approvers.yaml.

Why

The multi-approvers action requires secrets.MULTI_APPROVERS_TOKEN. Under GitHub Actions security restrictions, workflows triggered by pull request review events on forks do not have access to repository secrets. When reviews are submitted on fork PRs (such as Renovate bot PRs or external contributions), secrets.MULTI_APPROVERS_TOKEN evaluates to empty and the action fails with:
Multi-approvers action failed: input required and not supplied: token.

Solution

Removing pull_request_review aligns this workflow with the canonical configuration in googleapis/librarian and internal Cloud SDK standards (go/cloud-sdk-github-2p-reviews). For bot PRs, the initial pull_request_target run succeeds. For external fork PRs, approval status checks can be updated after two reviews by manually re-running the pull_request_target check.

The multi-approvers action requires secrets.MULTI_APPROVERS_TOKEN.
In GitHub Actions, workflows triggered by pull request events on forks
(including pull_request_review) do not have access to repository secrets.
When reviews are submitted on fork PRs (such as Renovate bot PRs),
the workflow fails with "input required and not supplied: token".

Removing pull_request_review aligns this workflow with the canonical
configuration in googleapis/librarian and prevents failures on fork PRs.
Approval re-evaluation on fork PRs can be performed by re-running the
pull_request_target check.
@hessjcg
hessjcg requested a review from a team as a code owner October 8, 2026 20:16
@hessjcg
hessjcg enabled auto-merge (squash) October 8, 2026 20:17
@hessjcg
hessjcg merged commit c1520eb into main Oct 8, 2026
14 of 15 checks passed
@hessjcg
hessjcg deleted the ci-fix-multi-approvers branch October 8, 2026 20:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants