+The daily `Pylon upstream sync` workflow updates `main` through GitHub's fork `merge-upstream` API, verifies that it exactly matches Prime, prepares one deterministic merge candidate, and runs a new candidate through the trusted `pylon` CI definition with no secrets or persisted Git credentials. An unchanged candidate skips duplicate CI only after the Actions API confirms that its stored run and candidate-bound aggregate succeeded. The workflow opens or updates one candidate-ready issue with a prefilled link and the exact draft title, body, label, and branch requirements. A conflict opens or updates one blocker issue and requires a human resolution branch from `pylon`; the workflow never resolves conflicts automatically.
0 commit comments