Note
I'm now using a newer version of this workflow that supports an allow list for individual packages and update groups which can be found here:
If you're using a workflow like this and need to manage secrets in multiple repos xt0rted/secrets-sync can simplify that. This lets you add secrets to one repo and sync them to many repos. There's also a template you can fork to get started quickly with it.