chore(ci): mint a GitHub App token for bump-version, drop BOT_TOKEN - #80
Merged
Merged
Conversation
datacoves-sa's classic PAT stopped working once the org blocked classic PATs. A short-lived installation token from a GitHub App scoped to Contents: read/write replaces it, and still counts as an external actor so creating the release fires release: published for release-package.yml, same as before.
Review of PR #80Scope: this PR only changes No blocking issues found. Two things worth checking before merge:
The action is pinned to a commit SHA, which is good. The diff includes no credential literals. |
This was referenced Sep 28, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Replace
secrets.BOT_TOKEN(a classic PAT fordatacoves-sa) with a short-lived token minted from a GitHub App installation, in the one workflow that used it.Why
The org now blocks classic PATs, so
bump-version.ymlfails on thegit push --tagsstep:BOT_TOKENwas only needed for one reason: creating the GitHub Release with the defaultGITHUB_TOKENwould not fire therelease: publishedevent, sorelease-package.yml(which publishes to PyPI) would never run. A token from an external actor (PAT or App installation) avoids that event suppression.A new GitHub App ("Datacoves snowcap",
Contents: read/write,Metadata: read-only, installed only on this repo) replaces the PAT.actions/create-github-app-tokenmints a ~1 hour installation token at the start of the job from theAPP_ID/APP_PRIVATE_KEYsecrets, used for both the version-bump push and the release creation.Verified
python3 -c "import yaml; yaml.safe_load(...)").APP_ID/APP_PRIVATE_KEYsecrets exist on the repo.FragileTech/bump-version'slogininput is only used as the HTTPS basic-auth username (https://<login>:<token>@github.com/...), confirmed by reading itsaction.yml—x-access-tokenis GitHub's documented convention for authenticating with an App installation token over HTTPS, in place of the olddatacoves-salogin.workflow_dispatchrun (which needsAPP_ID/APP_PRIVATE_KEYin Actions) hasn't been exercised yet — worth a manual dispatch run after merge to confirm end-to-end before deletingBOT_TOKEN.Follow-up
Once a real run succeeds, delete the now-unused
BOT_TOKENsecret.