Skip to content

Open the specification update pull request with a GitHub App token - #6

Merged
mageshb merged 1 commit into
mainfrom
spec-sync-github-app
Sep 22, 2026
Merged

mageshb merged 1 commit into
mainfrom
spec-sync-github-app

Conversation

@mageshb

@mageshb mageshb commented Sep 22, 2026

Copy link
Copy Markdown
Contributor

The daily spec-drift workflow now opens its pull request with a token from a GitHub App instead of a personal access token, so the pull request triggers CI and is authored by the app's bot account.

  • actions/create-github-app-token@v3 mints a token limited to contents and pull requests, from the SPEC_SYNC_APP_CLIENT_ID repository variable and the SPEC_SYNC_APP_PRIVATE_KEY repository secret.
  • The token step runs on every check, so an expired key or an uninstalled app fails the next daily run instead of going unnoticed.
  • Without the app, the workflow falls back to GITHUB_TOKEN as before.
  • MAINTAINING.md describes how to create, install and configure the app.

actionlint passes, apart from a false positive: its bundled metadata for create-github-app-token predates the client-id input, which exists from v3.1.

Pull requests opened with GITHUB_TOKEN do not trigger CI. The drift
workflow now mints a short-lived token from a GitHub App, configured with
the SPEC_SYNC_APP_CLIENT_ID variable and the SPEC_SYNC_APP_PRIVATE_KEY
secret, and uses the app's bot account as the author and committer. The
token step runs on every check so that a broken setup is noticed at once.
Without the app, the workflow falls back to GITHUB_TOKEN.

This replaces the SPEC_SYNC_TOKEN personal access token. MAINTAINING.md
describes how to create and install the app.
@mageshb
mageshb merged commit 0036d41 into main Sep 22, 2026
11 checks passed
@mageshb
mageshb deleted the spec-sync-github-app branch September 22, 2026 16:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant