diff --git a/.github/workflows/dated-todo-sweep.yml b/.github/workflows/dated-todo-sweep.yml index cd2da36c0ca86..855064571132a 100644 --- a/.github/workflows/dated-todo-sweep.yml +++ b/.github/workflows/dated-todo-sweep.yml @@ -25,7 +25,9 @@ jobs: analyze: # Manual runs may select a ref; secrets are available only when that ref is # the trusted default branch. Scheduled runs already target that branch. - if: github.event_name != 'workflow_dispatch' || github.ref == format('refs/heads/{0}', github.event.repository.default_branch) + # Forks lack OPENAI_API_KEY / GH_APP_PRIVATE_KEY(_FALLBACK), so scope the + # whole schedule to the canonical repo instead of failing every run. + if: github.repository == 'openclaw/openclaw' && (github.event_name != 'workflow_dispatch' || github.ref == format('refs/heads/{0}', github.event.repository.default_branch)) outputs: sweep-date: ${{ steps.sweep-date.outputs.date }} runs-on: ubuntu-24.04 @@ -75,7 +77,7 @@ jobs: retention-days: 7 upsert: - if: github.event_name != 'workflow_dispatch' || github.ref == format('refs/heads/{0}', github.event.repository.default_branch) + if: github.repository == 'openclaw/openclaw' && (github.event_name != 'workflow_dispatch' || github.ref == format('refs/heads/{0}', github.event.repository.default_branch)) needs: analyze runs-on: ubuntu-24.04 timeout-minutes: 10 diff --git a/.github/workflows/openclaw-performance.yml b/.github/workflows/openclaw-performance.yml index 2c2b5c4ed40f3..2cbdc5960dc66 100644 --- a/.github/workflows/openclaw-performance.yml +++ b/.github/workflows/openclaw-performance.yml @@ -196,6 +196,8 @@ jobs: secret_eligible=false cache_write_allowed=false if [[ + "$GITHUB_REPOSITORY" == "openclaw/openclaw" + ]] && [[ "$GITHUB_EVENT_NAME" == "schedule" || "$GITHUB_EVENT_NAME" == "workflow_dispatch" ]] && [[ diff --git a/.github/workflows/pr-ci-sweeper.yml b/.github/workflows/pr-ci-sweeper.yml index dd84e0d4ea1b6..4f5e40798cb32 100644 --- a/.github/workflows/pr-ci-sweeper.yml +++ b/.github/workflows/pr-ci-sweeper.yml @@ -26,6 +26,10 @@ permissions: {} jobs: sweep: + # This sweep authenticates as a GitHub App installed only on the canonical + # repo; forks lack GH_APP_PRIVATE_KEY(_FALLBACK), so the scheduled run would + # otherwise fail every hour with no actionable fix available to the fork owner. + if: github.repository == 'openclaw/openclaw' permissions: contents: read runs-on: ubuntu-24.04 diff --git a/.github/workflows/stale.yml b/.github/workflows/stale.yml index 094d76d2196b4..d7778c999d1fe 100644 --- a/.github/workflows/stale.yml +++ b/.github/workflows/stale.yml @@ -37,8 +37,11 @@ env: permissions: {} jobs: + # These jobs authenticate as GitHub Apps installed only on the canonical + # repo; forks lack GH_APP_PRIVATE_KEY(_FALLBACK), so every job below is + # scoped to openclaw/openclaw to avoid failing on every scheduled run. stale: - if: ${{ github.event_name != 'workflow_dispatch' || inputs.backfill_stale_closures != true }} + if: ${{ github.repository == 'openclaw/openclaw' && (github.event_name != 'workflow_dispatch' || inputs.backfill_stale_closures != true) }} permissions: issues: write pull-requests: write @@ -247,7 +250,7 @@ jobs: That channel is the escape hatch for high-quality PRs that get auto-closed. stale-bug-verification: - if: ${{ github.event_name != 'workflow_dispatch' || inputs.backfill_stale_closures != true }} + if: ${{ github.repository == 'openclaw/openclaw' && (github.event_name != 'workflow_dispatch' || inputs.backfill_stale_closures != true) }} permissions: issues: write runs-on: ubuntu-24.04 @@ -431,7 +434,7 @@ jobs: .write(); backfill-stale-closures: - if: ${{ github.event_name == 'workflow_dispatch' && inputs.backfill_stale_closures == true }} + if: ${{ github.repository == 'openclaw/openclaw' && github.event_name == 'workflow_dispatch' && inputs.backfill_stale_closures == true }} permissions: issues: write pull-requests: write @@ -684,7 +687,7 @@ jobs: audit-bug-closure-reasons: needs: stale - if: ${{ github.event_name != 'workflow_dispatch' || inputs.backfill_stale_closures != true }} + if: ${{ github.repository == 'openclaw/openclaw' && (github.event_name != 'workflow_dispatch' || inputs.backfill_stale_closures != true) }} permissions: issues: read runs-on: ubuntu-24.04 @@ -784,7 +787,7 @@ jobs: lock-closed-issues: needs: stale - if: ${{ github.event_name != 'workflow_dispatch' || inputs.backfill_stale_closures != true }} + if: ${{ github.repository == 'openclaw/openclaw' && (github.event_name != 'workflow_dispatch' || inputs.backfill_stale_closures != true) }} permissions: issues: write runs-on: blacksmith-16vcpu-ubuntu-2404