From aa673ed7a47ac78894e28c16a8454d55c3da3989 Mon Sep 17 00:00:00 2001 From: samuelburnham <45365069+samuelburnham@users.noreply.github.com> Date: Wed, 30 Sep 2026 12:26:33 -0400 Subject: [PATCH] chore: Gate update PR on lean4-nix version --- .github/workflows/update.yml | 20 +++++++------------- 1 file changed, 7 insertions(+), 13 deletions(-) diff --git a/.github/workflows/update.yml b/.github/workflows/update.yml index 87f3e8e..b84c49f 100644 --- a/.github/workflows/update.yml +++ b/.github/workflows/update.yml @@ -2,8 +2,8 @@ name: Update Lean toolchain and pinned deps on: schedule: - # Daily at 00:00 UTC - - cron: "0 0 * * *" + - cron: "0 12 * * *" + timezone: America/New_York workflow_dispatch: permissions: @@ -16,20 +16,14 @@ jobs: steps: - uses: actions/checkout@v7 - # Mint a token from the GitHub App so the opened PR triggers CI; pushes - # made with GITHUB_TOKEN do not. Same App as the org repo-sync workflows. - - uses: actions/create-github-app-token@v3 - id: app-token + - uses: cachix/install-nix-action@v31 with: - client-id: ${{ secrets.TOKEN_APP_ID }} - private-key: ${{ secrets.TOKEN_APP_PRIVATE_KEY }} + github_access_token: ${{ secrets.GITHUB_TOKEN }} - # `dev` carries the fork's bump_mode/release_channel support; `main` only - # mirrors upstream, which silently ignores these inputs. A PR is opened - # on an update/lean-{release} branch whether or not the build passes, so - # an incompatible release shows up as a failing PR to review. + # `dev` carries pinned-tag updates and lean4-nix gating; `main` only + # mirrors upstream and ignores these inputs. - uses: argumentcomputer/lean-update@dev with: bump_mode: pinned-tags on_update_fails: pr - token: ${{ steps.app-token.outputs.token }} + update_lean4_nix: true