Repository navigation
Use client ID for App token generation - #411
Conversation
It's now be recommended way to identify the app.
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (2)
WalkthroughTwo GitHub workflow files are updated to modify GitHub App authentication configuration. The Changes
🚥 Pre-merge checks | ✅ 3✅ Passed checks (3 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Pull request overview
Updates GitHub Actions workflows to generate GitHub App tokens using the App client ID (the currently recommended identifier) instead of the App ID.
Changes:
- Switch
actions/create-github-app-tokeninput fromapp-idtoclient-idin the release workflow. - Switch CI checker workflow from
secrets.APP_IDtovars.CLIENT_IDand update the input accordingly.
Reviewed changes
Copilot reviewed 2 out of 2 changed files in this pull request and generated 2 comments.
| File | Description |
|---|---|
| .github/workflows/release.yml | Uses client-id + vars.CLIENT_ID for app token generation in the release job. |
| .github/workflows/ci-checker.yml | Uses client-id + vars.CLIENT_ID for app token generation in CI checker merge job. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
| client-id: ${{ vars.CLIENT_ID }} | ||
| private-key: ${{ secrets.PRIVATE_KEY }} |
There was a problem hiding this comment.
This switches the token generation input to client-id and references a new vars.CLIENT_ID. The workflow will fail at runtime unless CLIENT_ID is configured as a repository or environment variable (for the Release environment). Ensure the repo/env configuration is updated accordingly, and remove any now-unused APP_ID variable/secret to avoid confusion.
| uses: actions/create-github-app-token@1b10c78c7865c340bc4f6099eb2f838309f1e8c3 # v3.1.1 | ||
| with: | ||
| app-id: ${{ secrets.APP_ID }} | ||
| client-id: ${{ vars.CLIENT_ID }} |
There was a problem hiding this comment.
This changes from ${{ secrets.APP_ID }} to ${{ vars.CLIENT_ID }}. Unless CLIENT_ID is defined as a repository variable or an environment variable for the CI-Checker environment, this step will fail. Please ensure the Actions variables/secrets are updated (and consider cleaning up the old APP_ID secret if it’s no longer used).
| client-id: ${{ vars.CLIENT_ID }} | |
| client-id: ${{ secrets.APP_ID }} |
close #
✏️ Description
It's now the recommended way to identify the app.