Skip to content

fix(bump-consumers): commit and open the PRs as the org's marola-bot… - #55

Draft
h0ffmann wants to merge 1 commit into
mainfrom
claude/47-bump-consumers-app-token
Draft

h0ffmann wants to merge 1 commit into
mainfrom
claude/47-bump-consumers-app-token

Conversation

@h0ffmann

@h0ffmann h0ffmann commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

Before: bump consumers pushes with the PAT behind MAROLA_CROSS_REPO_PAT. Its commits are attributed to github-actions[bot] and its PRs to whoever owns the token. Every consumer push was rejected because the token has no workflow permission.

After: the workflow mints a short-lived token for the org's GitHub App marola-bot (actions/create-github-app-token), and the commits and PRs are authored by marola-bot[bot]. No personal token is involved, so nothing expires.

How: bump-consumers.yml reads the org variable MAROLA_BOT_APP_ID and the org secret MAROLA_BOT_PRIVATE_KEY. It looks up the bot's user id to build the commit email and passes the name and email to bump-consumers.sh (BUMP_GIT_NAME/BUMP_GIT_EMAIL, defaulting to github-actions[bot]). release.yml passes the key through. docs/3-development.md gives the one-time App setup.

Part of #47.


Generated by Claude Code

…GitHub App

A PAT pushes as its owner and needs a workflow grant renewed by hand; an org App token is minted per run and names the automation as the author.

Tested: actionlint on both workflows, shellcheck and --self-test of bump-consumers.sh, tests/self-tests.sh
Cost: n/a (no measured figure in this cloud session)
Co-Authored-By: Claude <noreply@anthropic.com>
@github-actions github-actions Bot changed the title fix(bump-consumers): commit and open the PRs as the org's marola-bot GitHub App fix(bump-consumers): commit and open the PRs as the org's marola-bot… Oct 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants