Conversation
The action's `token` input defaults to `github.token` and overrides a GITHUB_TOKEN env var (per its own action.yml: "A non-empty explicit token overrides GITHUB_TOKEN"). Setting only the env var meant the release was still created with the default token, not the App's -- confirmed by the v1.0.33 release's author showing github-actions[bot], and no matching release-package.yml run for its release: published event.
Review of PR #82No issues found. The PR changes one workflow file,
|
Contributor
Author
|
Not needed — publishing to PyPI is done manually via workflow_dispatch, so bump-version.yml's release creation doesn't need to trigger anything. Dropping the release: published trigger from release-package.yml instead (separate PR). |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
bump-version.yml's "Create GitHub Release" step passes the App token via thetokeninput instead of aGITHUB_TOKENenv var.Why
PR #80 minted a GitHub App installation token specifically so creating the release would fire
release: publishedforrelease-package.yml, replacing the now-broken classic PAT. Butsoftprops/action-gh-release'stokeninput defaults to${{ github.token }}, and its ownaction.ymlsays: "A non-empty explicit token overrides GITHUB_TOKEN" — so the input always wins over an env var. Setting onlyenv: GITHUB_TOKENleft the action using the default built-in token.Confirmed on the first real run after #80 merged (v1.0.33):
authorisgithub-actions[bot], not the App's bot identity.release-package.ymlhas no run matching that release — therelease: publishedevent was suppressed, same failure mode chore(ci): mint a GitHub App token for bump-version, drop BOT_TOKEN #80 was meant to fix, just moved one step later.Verified
action.ymlforsoftprops/action-gh-release@v3confirms thetokeninput's precedence over the env var.workflow_dispatchrun) — the next bump-version run should show the release authored by the App's bot identity and a matchingrelease-package.ymlrun triggered by thereleaseevent.