Problem/Motivation
This project's GitHub development mirror (Wilkes-Liberty/graphql_compose_codegen) carries two GitHub Actions workflows that call reusable workflows hosted in the organization's private .github repository. A public repository cannot consume a reusable workflow from a private one, so both fail at workflow load on every pull request there — zero jobs, no logs:
.github/workflows/dependabot-automerge.yml.github/workflows/changelog-autoupdate.yml
This does not affect drupal.org packaging or releases; it is CI hygiene on the development mirror, recorded here because this queue is the project's canonical record. GitHub twin with run evidence: issue #29 on the mirror.
Proposed resolution
Remove changelog-autoupdate.yml rather than repairing it — it is deprecated organization-wide: it edited Dependabot pull requests, which blocks Dependabot from rebasing its own branches, and the changelog gate already exempts the bot author.
Inline dependabot-automerge.yml following the self-contained variant the mcp_sentinel and drupal-mcp-connector mirrors carry (same dependabot author exemption, patch/minor auto-merge only, majors left for review), or repoint it at the organization's public shared-CI repository once its shareable workflows migrate there. The mirror's changelog gate was already inlined for exactly the same load failure.
Remaining tasks
- Remove
.github/workflows/changelog-autoupdate.ymlon the mirror - Inline or repoint
.github/workflows/dependabot-automerge.yml
Comments
Comment #2
jmcerdaImplemented on the GitHub development mirror. The deprecated changelog autoupdate workflow is removed, and Dependabot auto-merge is now self-contained for public-repository workflow loading. The mirror pull request is open and its required CI checks are green.
Comment #4
jmcerdaReleased in 1.1.1. The public mirror workflows now load without private reusable-workflow dependencies, and Dependabot patch/minor auto-merge remains in place.