Repository navigation
Automatically update third party licenses during Dependabot PRs #11270
Description
Activity
One of the concerns raised that might prevent this from being automatically fixed is how GitHub Actions status checks are triggered by pushes using the
secrets.GITHUB_TOKENautomatic token.This concern is related to Triggering a workflow from a workflow where GitHub Actions might not automatically re-run the status checks on the original PR for changes made by a different workflow:
When you use the repository's GITHUB_TOKEN to perform tasks, events triggered by the GITHUB_TOKEN, with the exception of workflow_dispatch and repository_dispatch, will not create a new workflow run. This prevents you from accidentally creating recursive workflow runs. For example, if a workflow run pushes code using the repository's GITHUB_TOKEN, a new workflow will not run even when the repository contains a workflow configured to run when push events occur. For more information, see Use GITHUB_TOKEN in workflows.
In the event we cannot automatically fix this as described, then we will reopen and merge @williammartin work in #11269 as to reduce maintainer toil.
- addedenhancementa request to improve CLIa request to improve CLIcoreThis issue is not accepting PRs from outside contributorsThis issue is not accepting PRs from outside contributorsgithub_actionsPull requests that update GitHub Actions codePull requests that update GitHub Actions code
on Jul 15, 2025 - addeddiscussFeature changes that require discussion primarily among the GitHub CLI teamFeature changes that require discussion primarily among the GitHub CLI team
on Jul 17, 2025 - added a commit that references this issue
on Jul 23, 2025
Overview
With
cli/clilint process erring if 3rd party license information is not updated in #11047, Dependabot PRs will require maintainers to manually runmake licenses.Recently, @williammartin opened #11269 with the
script/fix-dependabot-licenses.shscript for maintainers to run that will find all Dependabot PRs and attempt to fix them where the lint workflow failed. This script is a manual repair effort, however it is possible to use a GitHub Actions workflow to run themake licensescript for Dependabot PRs:This issue is aimed at implementing GitHub Actions workflow changes that will automatically update
third-partylicense source code andthird-party-*.mdreports, eliminating the need for maintainers to manually repair Dependabot PRs.Note
To download the
script/fix-dependabot-licenses.shscript, run the following command:Or checkout the original PR:
Expected outcomes
make licenses