Repository navigation
ci(oc): Refactor workflows to use GitHub app - #1626
Conversation
Updated GitHub Actions workflow to use tokens generated by the create-github-app-token action for permissions on issues, pull requests, and contents.
|
/review |
lyra-the-bot
left a comment
There was a problem hiding this comment.
LGTM directionally - replacing long-lived PATs with short-lived per-step App tokens is the right move, and the permission split is sound: administration:read only for the collaborator check, issues/prs:write + contents:read for comments/context, contents:write isolated to the push step. persist-credentials:false + explicit PUSH_TOKEN credential-helper handling is preserved (and safe - literal $PUSH_TOKEN in the helper, expanded at runtime, not baked into the config). Verify ops side before merge: vars.LYRA_APP_ID + secrets.LYRA_PRIVATE_KEY exist and the Lyra App is installed on this repo with administration(read), issues/pull-requests(write), contents(read/write) granted, otherwise all three mints fail. Minor nits inline.
|
/review |
lyra-the-bot
left a comment
There was a problem hiding this comment.
LGTM. Incremental changes since last review all check out: client-id replaces app-id for token minting (supported by create-github-app-token@v3), bot committer identity now derives from app-slug output with proper ID+name[bot]@users.noreply email instead of hardcoded lyra-the-bot, review trigger uses format('{0}[bot]', vars.LYRA_SLUG), and triage/review workflows fully drop LYRA_PRS_ISSUES_PAT in favor of per-job minted tokens. Contents-write token correctly narrowed to contents:write only and gated on opencode success. Verified no secrets.*PAT* references remain in workflows. Same ops precondition as before: vars.LYRA_CLIENT_ID / vars.LYRA_SLUG + secrets.LYRA_PRIVATE_KEY must exist and the app installed with administration(read), issues/PRs(write), contents(read/write).
Summary by cubic
Tracks and replaces long-lived PAT secrets with short-lived GitHub App tokens minted per step in
opencode.yml,opencode_issue_triage.yml, andopencode_review.yml, so each step only gets the permissions it needs. The bot identity now derives from the app slug instead of the hardcodedlyra-the-bot.Refactors
actions/create-github-app-token.${LYRA_SLUG}[bot]with the app user id from the gh api; the review trigger checks the requested reviewer viaformat('{0}[bot]', vars.LYRA_SLUG).LYRA_CLIENT_ID,LYRA_PRIVATE_KEY, andLYRA_SLUGto be set;PAT_ADMIN_READ,LYRA_CONTENTS_PRS_ISSUES_PAT,PAT_CONTENTS_WRITE, andLYRA_PRS_ISSUES_PATare no longer used.Written for commit 93de381. Summary will update on new commits.