Skip to content

Fix release approval notifications - #24906

Draft
dkirov-dd wants to merge 1 commit into
masterfrom
bits/fix-release-notifications
Draft

Fix release approval notifications#24906
dkirov-dd wants to merge 1 commit into
masterfrom
bits/fix-release-notifications

Conversation

@dkirov-dd

Copy link
Copy Markdown
Contributor

What does this PR do?

Uses the dedicated integrations-core-release-notifications dd-sts policy when sending pending release approval notifications. The policy is introduced by https://github.com/ddoghq/dd-source/pull/59600 and grants the short-lived application key the required workflows_run permission.

Motivation

Release notification jobs are failing with HTTP 403 when triggering the Datadog notification workflow, including https://github.com/DataDog/integrations-core/actions/runs/31813285530. The generic integrations-core policy has no Workflow Automation RBAC permissions.

Review checklist (to be filled by reviewers)

  • Feature or bugfix MUST have appropriate tests (unit, integration, e2e)
  • Add qa/required if this PR needs QA validation, or qa/skip-qa if it does not. Exactly one of the two is required.
  • If you need to backport this PR to another branch, you can add the backport/<branch-name> label to the PR and it will automatically open a backport PR once this one is merged

@dkirov-dd dkirov-dd added the qa/skip-qa Automatically skip this PR for the next QA label Aug 18, 2026
@dd-octo-sts

dd-octo-sts Bot commented Aug 18, 2026

Copy link
Copy Markdown
Contributor

Validation Report

All 21 validations passed.

Show details
Validation Description Status
agent-reqs Verify check versions match the Agent requirements file
ci Validate CI configuration and code coverage settings
codeowners Validate every integration has a CODEOWNERS entry
config Validate default configuration files against spec.yaml
dep Verify dependency pins are consistent and Agent-compatible
http Validate integrations use the HTTP wrapper correctly
imports Validate check imports do not use deprecated modules
integration-style Validate check code style conventions
jmx-metrics Validate JMX metrics definition files and config
labeler Validate PR labeler config matches integration directories
legacy-signature Validate no integration uses the legacy Agent check signature
license-headers Validate Python files have proper license headers
licenses Validate third-party license attribution list
metadata Validate metadata.csv metric definitions
models Validate configuration data models match spec.yaml
openmetrics Validate OpenMetrics integrations disable the metric limit
package Validate Python package metadata and naming
qa-label Validate the pull request declares whether it needs QA for the next Agent release
readmes Validate README files have required sections
saved-views Validate saved view JSON file structure and fields
version Validate version consistency between package and changelog

View full run

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dev/testing dev/tooling qa/skip-qa Automatically skip this PR for the next QA

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant