From 09cc2eed62b37dbb54c331dfd6877f84ca17220d Mon Sep 17 00:00:00 2001 From: Noel Gomez Date: Mon, 28 Sep 2026 14:27:27 -0700 Subject: [PATCH] chore(ci): mint a GitHub App token for bump-version, drop BOT_TOKEN datacoves-sa's classic PAT stopped working once the org blocked classic PATs. A short-lived installation token from a GitHub App scoped to Contents: read/write replaces it, and still counts as an external actor so creating the release fires release: published for release-package.yml, same as before. --- .github/workflows/bump-version.yml | 12 +++++++++--- 1 file changed, 9 insertions(+), 3 deletions(-) diff --git a/.github/workflows/bump-version.yml b/.github/workflows/bump-version.yml index 7531444..e7659fb 100644 --- a/.github/workflows/bump-version.yml +++ b/.github/workflows/bump-version.yml @@ -14,6 +14,12 @@ jobs: with: persist-credentials: false fetch-depth: 0 + - name: actions/create-github-app-token + id: app-token + uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0 + with: + app-id: ${{ secrets.APP_ID }} + private-key: ${{ secrets.APP_PRIVATE_KEY }} - name: current_version run: echo "current_version=$(grep '# version' version.md | cut -d ' ' -f3)" >> $GITHUB_ENV - name: FragileTech/bump-version @@ -24,8 +30,8 @@ jobs: files: version.md commit_name: Datacoves Bot commit_email: support+snowcap@datacoves.com - login: datacoves-sa - token: "${{ secrets.BOT_TOKEN }}" + login: x-access-token + token: "${{ steps.app-token.outputs.token }}" - name: Read new version from version.md run: echo "next_version=$(grep '# version' version.md | cut -d ' ' -f3)" >> $GITHUB_ENV - name: Generate release notes from commits @@ -44,4 +50,4 @@ jobs: name: "v${{ env.next_version }}" body: ${{ steps.notes.outputs.notes }} env: - GITHUB_TOKEN: ${{ secrets.BOT_TOKEN }} + GITHUB_TOKEN: ${{ steps.app-token.outputs.token }}