Skip to content

fix(actions): standardize kicsbot automation branch names under feature/kicsbot-* - #8129

Open
cx-lior-poterman wants to merge 10 commits into
masterfrom
ast-171789-kicsbot-branch-prefix
Open

cx-lior-poterman wants to merge 10 commits into
masterfrom
ast-171789-kicsbot-branch-prefix

Conversation

@cx-lior-poterman

@cx-lior-poterman cx-lior-poterman commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

Automated PR-opening workflows push branches as the default GITHUB_TOKEN identity, which the org branch-creation ruleset does not exempt, so these pushes currently fail.

The ruleset is being updated separately to exclude the feature/kicsbot-* branch pattern. Two of the four affected workflows already use that prefix; this renames the branch used by prepare-release and update-docs-queries so all four share the exclusion.

No other behavior changes.

I submit this contribution under the Apache-2.0 license.

Automated PR-opening workflows push branches as the default
GITHUB_TOKEN identity, which the org's branch-creation ruleset
does not exempt, causing these workflows to fail to push.

The ruleset is being updated separately to exclude the
feature/kicsbot-* branch pattern. This renames the branches used
by prepare-release and update-docs-queries so all kicsbot
automation workflows share that exclusion.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@cx-lior-poterman
cx-lior-poterman requested a review from a team September 23, 2026 12:24
@cx-artur-ribeiro cx-artur-ribeiro changed the title AST-171789 Standardize kicsbot automation branch names under feature/kicsbot-* fix(actions): standardize kicsbot automation branch names under feature/kicsbot-* Sep 23, 2026
cx-bruno-silva
cx-bruno-silva previously approved these changes Sep 23, 2026

@cx-bruno-silva cx-bruno-silva left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

cx-rui-araujo
cx-rui-araujo previously approved these changes Sep 23, 2026
@stepsecurity-app

stepsecurity-app Bot commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

✅ Resolved — a later workflow run passed this policy check.

Original alert (resolved)

Security Policy Alert: Secret Policy Violation

This workflow run has been blocked by StepSecurity's secrets policy because it accesses secrets and the workflow file differs from the default branch.

Secret references detected:

  • secrets.STEP_SECURITY_API_KEY at line 70
  • secrets.GITHUB_TOKEN at line 180

To approve this workflow, please add the workflows-approved label to this PR.

Note: The label must be added by someone other than the PR author (cx-artur-ribeiro) or automation bots to ensure proper security review.

After the label is added, you can re-run the blocked workflow to proceed.

This workflow will be automatically approved once merged into the default branch.

For more information, see StepSecurity's Secret Exfiltration Policy documentation.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants