From a03fbca4b848c06dd08af1807bdfb6c175979bf2 Mon Sep 17 00:00:00 2001 From: Vitor Mattos Date: Tue, 22 Sep 2026 20:15:53 -0300 Subject: [PATCH 1/4] chore: modernize post-merge release actions --- actions/release-post-merge/action.yml | 49 +++++++++++++++++++-------- 1 file changed, 34 insertions(+), 15 deletions(-) diff --git a/actions/release-post-merge/action.yml b/actions/release-post-merge/action.yml index 78d5ace..827991f 100644 --- a/actions/release-post-merge/action.yml +++ b/actions/release-post-merge/action.yml @@ -22,9 +22,10 @@ inputs: github-token: description: Caller token used for artifact restore and permission lookup. required: true - app-id: - description: GitHub App id used for short-lived mutation tokens. - required: true + app-slug: + description: Public GitHub App slug used to resolve its client id. + required: false + default: librecode-workflow-automation app-private-key: description: GitHub App private key used for short-lived mutation tokens. required: true @@ -52,17 +53,13 @@ runs: - name: Validate GitHub App credentials shell: bash env: - RELEASE_APP_ID: ${{ inputs.app-id }} + RELEASE_APP_SLUG: ${{ inputs.app-slug }} RELEASE_APP_PRIVATE_KEY: ${{ inputs.app-private-key }} run: | set -euo pipefail - if [[ -z "${RELEASE_APP_ID}" ]]; then - echo "::error::GitHub App id is empty. Configure LIBRECODE_WORKFLOW_APP_ID as an Actions variable in the consumer repository or organization." - exit 1 - fi - if [[ ! "${RELEASE_APP_ID}" =~ ^[0-9]+$ ]]; then - echo "::error::GitHub App id must be numeric." + if [[ -z "${RELEASE_APP_SLUG}" ]]; then + echo "::error::GitHub App slug is empty." exit 1 fi if [[ -z "${RELEASE_APP_PRIVATE_KEY}" ]]; then @@ -116,11 +113,33 @@ runs: echo "owner=${RELEASE_REPOSITORY%%/*}" >> "${GITHUB_OUTPUT}" echo "name=${RELEASE_REPOSITORY#*/}" >> "${GITHUB_OUTPUT}" + - id: app-identity + name: Resolve GitHub App client id + shell: bash + env: + RELEASE_APP_SLUG: ${{ inputs.app-slug }} + RELEASE_GITHUB_TOKEN: ${{ inputs.github-token }} + RELEASE_GITHUB_API_URL: ${{ github.api_url }} + run: | + set -euo pipefail + + app_json="$(curl --fail --silent --show-error --location \ + -H "Accept: application/vnd.github+json" \ + -H "Authorization: Bearer ${RELEASE_GITHUB_TOKEN}" \ + -H "X-GitHub-Api-Version: 2022-11-28" \ + "${RELEASE_GITHUB_API_URL}/apps/${RELEASE_APP_SLUG}")" + client_id="$(php -r '$d=json_decode(stream_get_contents(STDIN),true,512,JSON_THROW_ON_ERROR); echo $d["client_id"] ?? "";' <<< "${app_json}")" + if [[ -z "${client_id}" ]]; then + echo "::error::GitHub App metadata did not contain a client_id for ${RELEASE_APP_SLUG}." + exit 1 + fi + echo "client-id=${client_id}" >> "${GITHUB_OUTPUT}" + - id: finalization-token name: Create finalization token - uses: actions/create-github-app-token@67018539274d69449ef7c02e8e71183d1719ab42 # v2.1.4 + uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0 with: - app-id: ${{ inputs.app-id }} + client-id: ${{ steps.app-identity.outputs.client-id }} private-key: ${{ inputs.app-private-key }} owner: ${{ steps.repository.outputs.owner }} repositories: ${{ steps.repository.outputs.name }} @@ -180,9 +199,9 @@ runs: - id: draft-token name: Create release draft token - uses: actions/create-github-app-token@67018539274d69449ef7c02e8e71183d1719ab42 # v2.1.4 + uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0 with: - app-id: ${{ inputs.app-id }} + client-id: ${{ steps.app-identity.outputs.client-id }} private-key: ${{ inputs.app-private-key }} owner: ${{ steps.repository.outputs.owner }} repositories: ${{ steps.repository.outputs.name }} @@ -234,7 +253,7 @@ runs: } >> "${GITHUB_STEP_SUMMARY}" - name: Persist finalized release contracts - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: ${{ steps.draft.outputs.state-artifact-name }} path: ${{ runner.temp }}/release-post-merge-state From c9a9d6bbd313c8b37d1eb21d61ec4c1547d21615 Mon Sep 17 00:00:00 2001 From: Vitor Mattos Date: Tue, 22 Sep 2026 20:15:56 -0300 Subject: [PATCH 2/4] test: require modern post-merge release actions --- tests/test_release_post_merge_action.py | 10 +++++++--- 1 file changed, 7 insertions(+), 3 deletions(-) diff --git a/tests/test_release_post_merge_action.py b/tests/test_release_post_merge_action.py index 4c502d9..bfbad3b 100644 --- a/tests/test_release_post_merge_action.py +++ b/tests/test_release_post_merge_action.py @@ -15,8 +15,11 @@ def test_credentials_are_validated_before_artifact_restore(self) -> None: validate = content.index("Validate GitHub App credentials") restore = content.index("Restore preparation contracts") self.assertLess(validate, restore) - self.assertIn("LIBRECODE_WORKFLOW_APP_ID", content) self.assertIn("LIBRECODE_WORKFLOW_APP_PRIVATE_KEY", content) + self.assertIn("librecode-workflow-automation", content) + self.assertIn("/apps/${RELEASE_APP_SLUG}", content) + self.assertNotIn("\n app-id:", content) + self.assertNotIn("inputs.app-id", content) def test_authorization_happens_before_mutation(self) -> None: content = ACTION.read_text(encoding="utf-8") @@ -31,7 +34,8 @@ def test_authorization_happens_before_mutation(self) -> None: def test_mutating_stages_use_scoped_tokens(self) -> None: content = ACTION.read_text(encoding="utf-8") - self.assertEqual(2, content.count("actions/create-github-app-token@67018539274d69449ef7c02e8e71183d1719ab42")) + self.assertEqual(2, content.count("actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1")) + self.assertEqual(2, content.count("client-id: ${{ steps.app-identity.outputs.client-id }}")) self.assertIn("permission-contents: write", content) self.assertIn("permission-pull-requests: write", content) self.assertNotIn("permission-issues: write", content) @@ -51,7 +55,7 @@ def test_contract_chain_is_persisted_for_publication(self) -> None: self.assertIn("milestone:transition", content) self.assertIn("release:draft", content) self.assertIn('artifact_name="release-state-${release_id}"', content) - self.assertIn("actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02", content) + self.assertIn("actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a", content) def test_restore_action_can_bind_artifact_to_origin_workflow(self) -> None: content = RESTORE.read_text(encoding="utf-8") From 1b689d63f726964913944640f323b86f0b7f9245 Mon Sep 17 00:00:00 2001 From: Vitor Mattos Date: Tue, 22 Sep 2026 20:16:09 -0300 Subject: [PATCH 3/4] chore: modernize catalog GitHub App authentication --- .github/workflows/catalog-publish.yml | 23 ++++++++++++++++------- 1 file changed, 16 insertions(+), 7 deletions(-) diff --git a/.github/workflows/catalog-publish.yml b/.github/workflows/catalog-publish.yml index 94a1b2e..896eec7 100644 --- a/.github/workflows/catalog-publish.yml +++ b/.github/workflows/catalog-publish.yml @@ -25,23 +25,32 @@ jobs: steps: - name: Validate GitHub App configuration env: - WORKFLOW_APP_ID: ${{ vars.LIBRECODE_WORKFLOW_APP_ID }} WORKFLOW_APP_PRIVATE_KEY: ${{ secrets.LIBRECODE_WORKFLOW_APP_PRIVATE_KEY }} run: | - if [ -z "$WORKFLOW_APP_ID" ]; then - echo "::error::LIBRECODE_WORKFLOW_APP_ID is not configured." - exit 1 - fi if [ -z "$WORKFLOW_APP_PRIVATE_KEY" ]; then echo "::error::LIBRECODE_WORKFLOW_APP_PRIVATE_KEY is not configured." exit 1 fi + - name: Resolve GitHub App client id + id: app-identity + env: + GH_TOKEN: ${{ github.token }} + WORKFLOW_APP_SLUG: librecode-workflow-automation + run: | + set -euo pipefail + client_id="$(gh api "/apps/${WORKFLOW_APP_SLUG}" --jq .client_id)" + if [ -z "$client_id" ]; then + echo "::error::GitHub App metadata did not contain a client_id." + exit 1 + fi + echo "client-id=$client_id" >> "$GITHUB_OUTPUT" + - name: Create GitHub App token id: app-token - uses: actions/create-github-app-token@67018539274d69449ef7c02e8e71183d1719ab42 # v2.1.4 + uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0 with: - app-id: ${{ vars.LIBRECODE_WORKFLOW_APP_ID }} + client-id: ${{ steps.app-identity.outputs.client-id }} private-key: ${{ secrets.LIBRECODE_WORKFLOW_APP_PRIVATE_KEY }} owner: LibreCodeCoop repositories: .github From 63438c060a6338ba0ba7bb81f1dadd8d64ba42d9 Mon Sep 17 00:00:00 2001 From: Vitor Mattos Date: Tue, 22 Sep 2026 20:16:18 -0300 Subject: [PATCH 4/4] chore: bump version to 0.6.24 --- VERSION | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/VERSION b/VERSION index 9d04cbd..0426003 100644 --- a/VERSION +++ b/VERSION @@ -1 +1 @@ -0.6.23 +0.6.24