Skip to content

fix(bump-consumers): reuse the org secret MAROLA_CROSS_REPO_PAT - #54

Merged
h0ffmann merged 1 commit into
mainfrom
claude/47-bump-consumers-org-pat
Oct 8, 2026
Merged

h0ffmann merged 1 commit into
mainfrom
claude/47-bump-consumers-org-pat

Conversation

@h0ffmann

@h0ffmann h0ffmann commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

Summary: bump consumers no longer needs a new MAROLA_BUMP_TOKEN. It uses the org secret MAROLA_CROSS_REPO_PAT that every repo already passes to notify-umbrella. h0ffmann/ww3-gpu leaves .github/consumers.txt, since a fine-grained org token can't reach a personal repo; its two pins in skills.yml are bumped by hand.

MIP none — follow-up to #47
Tested ✅ gates · ⬜ e2e · ⬜ live · ⬜ ci-only: actionlint; shellcheck; bump-consumers.sh --self-test; tests/self-tests.sh; docs-lint
Cost n/a (no measured figure in this cloud session)

Still needed, once, in GitHub settings: the org secret's repository access must include marola-devkit, and the fine-grained token behind it needs Workflows: Read and write (the bump edits .github/workflows/) next to the Contents and Pull requests write it already uses for pointer-sync. Editing a fine-grained token's permissions keeps its value, so the secret itself doesn't change.


Generated by Claude Code

…ew token

The workflow asked for a new MAROLA_BUMP_TOKEN, a classic PAT, only so one token could reach
h0ffmann/ww3-gpu as well as the org. It now uses the org secret every repo already passes to
notify-umbrella, and ww3-gpu leaves the consumer list: its two pins are bumped by hand.

Tested: actionlint; shellcheck; bump-consumers.sh --self-test; tests/self-tests.sh; docs-lint
Cost: n/a (no measured figure in this cloud session)
Co-Authored-By: Claude <noreply@anthropic.com>
@github-actions github-actions Bot changed the title fix(bump-consumers): reuse the org secret MAROLA_CROSS_REPO_PAT, no new token fix(bump-consumers): reuse the org secret MAROLA_CROSS_REPO_PAT Oct 8, 2026
@h0ffmann
h0ffmann merged commit 8c73406 into main Oct 8, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants