The same thing applies for other bots. I don't understand why you don't allow the CodeOwner feature to prevent updating workflows, and then allow the github action bot to push to the same branch that triggered it. Right now practically I have to choose between protecting branches and using Github Actions on that branch.
... View more