Skip to content

ci: authenticate cross-repository automation with GitHub App - #35

Merged
vitormattos merged 7 commits into
mainfrom
feat/use-github-app-token
Sep 20, 2026
Merged

vitormattos merged 7 commits into
mainfrom
feat/use-github-app-token

Conversation

@vitormattos

Copy link
Copy Markdown
Member

Summary

Replace the static WORKFLOW_UPDATE_TOKEN contract with short-lived GitHub App installation tokens.

The installed LibreCode Workflow Automation App now provides authentication for:

  • publishing workflow-templates/ to LibreCodeCoop/.github;
  • synchronizing managed workflows into consumer repositories.

Authentication model

Each write-capable job now:

  1. validates LIBRECODE_WORKFLOW_APP_ID and LIBRECODE_WORKFLOW_APP_PRIVATE_KEY;
  2. creates a short-lived installation token using actions/create-github-app-token pinned to commit 67018539274d69449ef7c02e8e71183d1719ab42 (v2.1.4);
  3. requests only:
    • contents: write;
    • pull requests: write;
    • workflows: write;
  4. uses that token for cross-repository checkout and PR creation.

The matrix-building job remains read-only and does not generate an App token.

Validation

After merge, the push to main will trigger both:

  • Publish workflow catalog;
  • Sync consumer workflows.

Those runs will validate the App ID/private key and real cross-repository access configured in #20.

@vitormattos
vitormattos merged commit 9ef2cb3 into main Sep 20, 2026
4 of 5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant