Repository navigation
Open the specification update pull request with a GitHub App token - #6
Merged
Merged
Conversation
Pull requests opened with GITHUB_TOKEN do not trigger CI. The drift workflow now mints a short-lived token from a GitHub App, configured with the SPEC_SYNC_APP_CLIENT_ID variable and the SPEC_SYNC_APP_PRIVATE_KEY secret, and uses the app's bot account as the author and committer. The token step runs on every check so that a broken setup is noticed at once. Without the app, the workflow falls back to GITHUB_TOKEN. This replaces the SPEC_SYNC_TOKEN personal access token. MAINTAINING.md describes how to create and install the app.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The daily spec-drift workflow now opens its pull request with a token from a GitHub App instead of a personal access token, so the pull request triggers CI and is authored by the app's bot account.
actions/create-github-app-token@v3mints a token limited to contents and pull requests, from theSPEC_SYNC_APP_CLIENT_IDrepository variable and theSPEC_SYNC_APP_PRIVATE_KEYrepository secret.GITHUB_TOKENas before.actionlint passes, apart from a false positive: its bundled metadata for create-github-app-token predates the
client-idinput, which exists from v3.1.