Skip to content

tag-bump/release-bump: mint App token so bump PRs trigger CI - #23

Merged
TeoSlayer merged 1 commit into
mainfrom
feat/app-token-minting
Jul 13, 2026
Merged

TeoSlayer merged 1 commit into
mainfrom
feat/app-token-minting

Conversation

@TeoSlayer

Copy link
Copy Markdown
Contributor

Final link in the cascade chain: GITHUB_TOKEN-created PRs never trigger workflows, so required checks sat unreported on bump PRs. Both reusable workflows now mint a pilot-release-bot installation token from the new org secrets (scoped to the 18 cascade repos) and push/PR as the App — whose events do trigger CI. Fallback to github.token when secrets absent. Receivers switch to secrets: inherit in a follow-up wave.

🤖 Generated with Claude Code

…er CI

PRs and pushes made with the default GITHUB_TOKEN never trigger
workflows (recursion guard), so the required 'test' check sat
unreported on every bump PR and the merge gate never opened. Both
reusable workflows now optionally accept RELEASE_APP_ID /
RELEASE_APP_PRIVATE_KEY (org secrets, scoped to the 18 cascade repos),
mint an installation token, re-point the git remote at it (checkout's
persisted extraheader would otherwise win), and create the PR as the
App — whose events DO trigger CI. Falls back to github.token when the
secrets are absent.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@TeoSlayer
TeoSlayer merged commit 34e1809 into main Jul 13, 2026
@TeoSlayer
TeoSlayer deleted the feat/app-token-minting branch July 13, 2026 09:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants