diff --git a/.github/actions/get-app-token/action.yml b/.github/actions/get-app-token/action.yml index d42e46e813..611533f283 100644 --- a/.github/actions/get-app-token/action.yml +++ b/.github/actions/get-app-token/action.yml @@ -5,23 +5,24 @@ description: >- 5,000 req/hr per installation (vs 1,000 for the default GITHUB_TOKEN) and are scoped to the App's installation permissions, not a user account. - Falls back to the built-in GITHUB_TOKEN when APP_ID is not set — this - happens on fork PRs where repo secrets are unavailable. The fallback + Falls back to the built-in GITHUB_TOKEN when APP_CLIENT_ID is not set — + this happens on fork PRs where repo secrets are unavailable. The fallback ensures classification, timings, and review comments still work on forks (with the lower GITHUB_TOKEN rate limit). - Requires two repo secrets (store when creating the App): - - APP_ID — the App's numeric ID (Settings → General) - - APP_PRIVATE_KEY — the PEM private key (Settings → Private keys) - - The App must be installed on the repository (or org) with the - permissions the calling workflow needs. + Composite actions cannot access the secrets context directly, so the + calling workflow must pass secrets.APP_CLIENT_ID and secrets.APP_PRIVATE_KEY + as inputs. When both are empty (fork PRs), the fallback fires. inputs: - owner: - description: Repository owner (for cross-org tokens). Defaults to the current repo's owner. + client-id: + description: GitHub App Client ID. Pass secrets.APP_CLIENT_ID from the calling workflow. required: false - default: ${{ github.repository_owner }} + default: '' + private-key: + description: GitHub App private key PEM. Pass secrets.APP_PRIVATE_KEY from the calling workflow. + required: false + default: '' outputs: token: @@ -35,9 +36,9 @@ runs: id: check shell: bash env: - APP_ID: ${{ secrets.APP_ID }} + CLIENT_ID: ${{ inputs.client-id }} run: | - if [ -n "$APP_ID" ]; then + if [ -n "$CLIENT_ID" ]; then echo "has_app=true" >> "$GITHUB_OUTPUT" else echo "has_app=false" >> "$GITHUB_OUTPUT" @@ -48,9 +49,8 @@ runs: if: steps.check.outputs.has_app == 'true' uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0 with: - app-id: ${{ secrets.APP_ID }} - private-key: ${{ secrets.APP_PRIVATE_KEY }} - owner: ${{ inputs.owner }} + client-id: ${{ inputs.client-id }} + private-key: ${{ inputs.private-key }} - name: Fall back to GITHUB_TOKEN id: fallback diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index d22dc33815..6bb8876bcf 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -52,6 +52,9 @@ jobs: - name: Get GitHub App token id: app-token uses: ./.github/actions/get-app-token + with: + client-id: ${{ secrets.APP_CLIENT_ID }} + private-key: ${{ secrets.APP_PRIVATE_KEY }} - name: Detect affected areas id: classify uses: ./.github/actions/detect-changes @@ -324,6 +327,9 @@ jobs: - name: Get GitHub App token id: app-token uses: ./.github/actions/get-app-token + with: + client-id: ${{ secrets.APP_CLIENT_ID }} + private-key: ${{ secrets.APP_PRIVATE_KEY }} - name: Restore baseline cache (PR only) if: github.event_name == 'pull_request' diff --git a/.github/workflows/deploy-site.yml b/.github/workflows/deploy-site.yml index f03dbf8ec8..fd09205a05 100644 --- a/.github/workflows/deploy-site.yml +++ b/.github/workflows/deploy-site.yml @@ -59,6 +59,9 @@ jobs: - name: Get GitHub App token id: app-token uses: ./.github/actions/get-app-token + with: + client-id: ${{ secrets.APP_CLIENT_ID }} + private-key: ${{ secrets.APP_PRIVATE_KEY }} - uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4 with: diff --git a/.github/workflows/js-autofix.yml b/.github/workflows/js-autofix.yml index be8b8b4473..8fb0460bc0 100644 --- a/.github/workflows/js-autofix.yml +++ b/.github/workflows/js-autofix.yml @@ -131,6 +131,9 @@ jobs: - name: Get GitHub App token id: app-token uses: ./.github/actions/get-app-token + with: + client-id: ${{ secrets.APP_CLIENT_ID }} + private-key: ${{ secrets.APP_PRIVATE_KEY }} - name: Download patch uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4 diff --git a/.github/workflows/skills-index-freshness.yml b/.github/workflows/skills-index-freshness.yml index 70fc5c6da2..4931ccaa01 100644 --- a/.github/workflows/skills-index-freshness.yml +++ b/.github/workflows/skills-index-freshness.yml @@ -112,6 +112,9 @@ jobs: if: steps.probe.outputs.status != 'ok' id: app-token uses: ./.github/actions/get-app-token + with: + client-id: ${{ secrets.APP_CLIENT_ID }} + private-key: ${{ secrets.APP_PRIVATE_KEY }} - name: Open issue on degraded / failed probe if: steps.probe.outputs.status != 'ok' diff --git a/.github/workflows/skills-index.yml b/.github/workflows/skills-index.yml index 5f8259b278..ae05c9e704 100644 --- a/.github/workflows/skills-index.yml +++ b/.github/workflows/skills-index.yml @@ -27,6 +27,9 @@ jobs: - name: Get GitHub App token id: app-token uses: ./.github/actions/get-app-token + with: + client-id: ${{ secrets.APP_CLIENT_ID }} + private-key: ${{ secrets.APP_PRIVATE_KEY }} - uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0 with: @@ -61,6 +64,9 @@ jobs: - name: Get GitHub App token id: app-token uses: ./.github/actions/get-app-token + with: + client-id: ${{ secrets.APP_CLIENT_ID }} + private-key: ${{ secrets.APP_PRIVATE_KEY }} - name: Trigger Deploy Site workflow env: GH_TOKEN: ${{ steps.app-token.outputs.token }} diff --git a/.github/workflows/supply-chain-audit.yml b/.github/workflows/supply-chain-audit.yml index f4ba220917..1b8a35cb30 100644 --- a/.github/workflows/supply-chain-audit.yml +++ b/.github/workflows/supply-chain-audit.yml @@ -63,6 +63,9 @@ jobs: - name: Get GitHub App token id: app-token uses: ./.github/actions/get-app-token + with: + client-id: ${{ secrets.APP_CLIENT_ID }} + private-key: ${{ secrets.APP_PRIVATE_KEY }} - name: Scan diff for critical patterns id: scan diff --git a/.github/workflows/upload_to_pypi.yml b/.github/workflows/upload_to_pypi.yml index 1c56d2978c..e95ef194fa 100644 --- a/.github/workflows/upload_to_pypi.yml +++ b/.github/workflows/upload_to_pypi.yml @@ -146,6 +146,9 @@ jobs: - name: Get GitHub App token id: app-token uses: ./.github/actions/get-app-token + with: + client-id: ${{ secrets.APP_CLIENT_ID }} + private-key: ${{ secrets.APP_PRIVATE_KEY }} - name: Wait for GitHub Release to exist env: