From 3c68e7a81fd3bcfdcf1a575788629504e5969ac1 Mon Sep 17 00:00:00 2001 From: Vitor Mattos Date: Wed, 23 Sep 2026 16:58:09 -0300 Subject: [PATCH 1/3] chore: update GitHub App token action patch Signed-off-by: Vitor Mattos --- patches/nextcloud/sync-workflow-templates.yml.patch | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/patches/nextcloud/sync-workflow-templates.yml.patch b/patches/nextcloud/sync-workflow-templates.yml.patch index 076776a..f3ba378 100644 --- a/patches/nextcloud/sync-workflow-templates.yml.patch +++ b/patches/nextcloud/sync-workflow-templates.yml.patch @@ -76,7 +76,7 @@ + - name: Create LibreCode GitHub App token + if: ${{ vars.WORKFLOW_SYNC_AUTH_MODE == '' || vars.WORKFLOW_SYNC_AUTH_MODE == 'librecode-app' }} + id: librecode-app-token -+ uses: actions/create-github-app-token@67018539274d69449ef7c02e8e71183d1719ab42 # v2.1.4 ++ uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0 + with: + app-id: ${{ vars.LIBRECODE_WORKFLOW_APP_ID }} + private-key: ${{ secrets.LIBRECODE_WORKFLOW_APP_PRIVATE_KEY }} @@ -89,7 +89,7 @@ + - name: Create consumer GitHub App token + if: ${{ vars.WORKFLOW_SYNC_AUTH_MODE == 'github-app' }} + id: consumer-app-token -+ uses: actions/create-github-app-token@67018539274d69449ef7c02e8e71183d1719ab42 # v2.1.4 ++ uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0 + with: + app-id: ${{ vars.WORKFLOW_SYNC_APP_ID }} + private-key: ${{ secrets.WORKFLOW_SYNC_APP_PRIVATE_KEY }} From fa4b39f939ecdd59c93505f2c9c955f976471c0b Mon Sep 17 00:00:00 2001 From: Vitor Mattos Date: Wed, 23 Sep 2026 16:58:12 -0300 Subject: [PATCH 2/3] chore: update GitHub App token action template Signed-off-by: Vitor Mattos --- workflow-templates/sync-workflow-templates.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/workflow-templates/sync-workflow-templates.yml b/workflow-templates/sync-workflow-templates.yml index a0e59f2..4f76511 100644 --- a/workflow-templates/sync-workflow-templates.yml +++ b/workflow-templates/sync-workflow-templates.yml @@ -84,7 +84,7 @@ jobs: - name: Create LibreCode GitHub App token if: ${{ vars.WORKFLOW_SYNC_AUTH_MODE == '' || vars.WORKFLOW_SYNC_AUTH_MODE == 'librecode-app' }} id: librecode-app-token - uses: actions/create-github-app-token@67018539274d69449ef7c02e8e71183d1719ab42 # v2.1.4 + uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0 with: app-id: ${{ vars.LIBRECODE_WORKFLOW_APP_ID }} private-key: ${{ secrets.LIBRECODE_WORKFLOW_APP_PRIVATE_KEY }} @@ -97,7 +97,7 @@ jobs: - name: Create consumer GitHub App token if: ${{ vars.WORKFLOW_SYNC_AUTH_MODE == 'github-app' }} id: consumer-app-token - uses: actions/create-github-app-token@67018539274d69449ef7c02e8e71183d1719ab42 # v2.1.4 + uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0 with: app-id: ${{ vars.WORKFLOW_SYNC_APP_ID }} private-key: ${{ secrets.WORKFLOW_SYNC_APP_PRIVATE_KEY }} From ff24b25912449a373fb05e725964881639c575cd Mon Sep 17 00:00:00 2001 From: Vitor Mattos Date: Wed, 23 Sep 2026 16:58:14 -0300 Subject: [PATCH 3/3] test: prevent GitHub App token action downgrade Signed-off-by: Vitor Mattos --- tests/test_portable_workflow_sync_auth.py | 12 ++++++++++++ 1 file changed, 12 insertions(+) diff --git a/tests/test_portable_workflow_sync_auth.py b/tests/test_portable_workflow_sync_auth.py index b7feb77..ebac5d5 100644 --- a/tests/test_portable_workflow_sync_auth.py +++ b/tests/test_portable_workflow_sync_auth.py @@ -36,6 +36,18 @@ def test_librecode_app_credentials_use_actions_variable_and_secret(self) -> None self.assertIn("app-id: ${{ vars.LIBRECODE_WORKFLOW_APP_ID }}", content) self.assertNotIn("secrets.LIBRECODE_WORKFLOW_APP_ID", content) + def test_github_app_token_action_is_current_and_pinned(self) -> None: + content = TEMPLATE.read_text(encoding="utf-8") + sha = "bcd2ba49218906704ab6c1aa796996da409d3eb1" + + self.assertEqual( + content.count( + f"actions/create-github-app-token@{sha} # v3.2.0" + ), + 2, + ) + self.assertNotIn("actions/create-github-app-token@67018539274d69449ef7c02e8e71183d1719ab42", content) + def test_generated_pull_request_uses_selected_token(self) -> None: content = TEMPLATE.read_text(encoding="utf-8")