mirror of
https://github.com/J3vb/OwnCord.git
synced 2026-09-03 03:50:00 +03:00
Dependabot PRs run under the separate `dependabot` secrets scope, so TAURI_SIGNING_PRIVATE_KEY arrives empty and `npm run tauri build` always aborted with "failed to decode secret key" while signing the updater artifact -- after the compile and the NSIS/AppImage/deb bundle had both already succeeded. Every dependency PR therefore burned ~50 min of runner time across three platforms to produce a red check carrying no signal, and the permanent red masked whether the job would have caught a real break. Granting Dependabot the signing secret would clear the symptom but hands a release signing key to workflows triggered by third-party dependency updates, so the job is skipped for that actor instead. Coverage is preserved where it matters: `rust-tests` is a required check, runs on every event, and compiles the crate via `cargo clippy --all-targets` and `cargo test --lib`, so a dependency bump that breaks the Rust build is still caught. Given up on Dependabot PRs only: bundling, Windows/ARM-specific compilation, and the `cargo audit` step -- which overlaps with Dependabot's own cargo scanning. `Tauri Full Build` is not among the required status checks on main (Server Build & Test x2, Client Static Checks, Client Unit Tests, Rust Unit Tests), so skipping it cannot leave a PR waiting on a status. Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>