Skip to content

Use client ID for App token generation - #411

Merged
5ouma merged 1 commit into
mainfrom
ci-actions-app-client-id
Apr 18, 2026
Merged

5ouma merged 1 commit into
mainfrom
ci-actions-app-client-id

Conversation

@5ouma

@5ouma 5ouma commented Apr 18, 2026

Copy link
Copy Markdown
Owner

⚠️ Issue

close #


✏️ Description

It's now the recommended way to identify the app.


It's now be recommended way to identify the app.
Copilot AI review requested due to automatic review settings April 18, 2026 06:23
@github-actions github-actions Bot added the 🎽 CI Changes to CI configuration files and scripts label Apr 18, 2026
@coderabbitai

coderabbitai Bot commented Apr 18, 2026

Copy link
Copy Markdown

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 4102e489-7b66-47db-ac16-f9683037c212

📥 Commits

Reviewing files that changed from the base of the PR and between 4ba2415 and d9cbd41.

📒 Files selected for processing (2)
  • .github/workflows/ci-checker.yml
  • .github/workflows/release.yml

Walkthrough

Two GitHub workflow files are updated to modify GitHub App authentication configuration. The app-id input parameter is replaced with client-id in the actions/create-github-app-token action, while maintaining the private-key reference and permission settings across both workflows.

Changes

Cohort / File(s) Summary
GitHub App Authentication Updates
.github/workflows/ci-checker.yml, .github/workflows/release.yml
Modified GitHub App token generation by replacing app-id input with client-id in the actions/create-github-app-token action. The private-key source and permission configurations (permission-contents, permission-pull-requests) remain unchanged.
🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check name Status Explanation
Title check ✅ Passed The title accurately summarizes the main change: replacing app-id with client-id for GitHub App token generation in the workflow files.
Description check ✅ Passed The description is related to the changeset, explaining that using client ID is now the recommended way to identify the app.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch ci-actions-app-client-id

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@5ouma
5ouma merged commit 23dd948 into main Apr 18, 2026
14 checks passed
@5ouma
5ouma deleted the ci-actions-app-client-id branch April 18, 2026 06:25

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates GitHub Actions workflows to generate GitHub App tokens using the App client ID (the currently recommended identifier) instead of the App ID.

Changes:

  • Switch actions/create-github-app-token input from app-id to client-id in the release workflow.
  • Switch CI checker workflow from secrets.APP_ID to vars.CLIENT_ID and update the input accordingly.

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated 2 comments.

File Description
.github/workflows/release.yml Uses client-id + vars.CLIENT_ID for app token generation in the release job.
.github/workflows/ci-checker.yml Uses client-id + vars.CLIENT_ID for app token generation in CI checker merge job.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment on lines +27 to 28
client-id: ${{ vars.CLIENT_ID }}
private-key: ${{ secrets.PRIVATE_KEY }}

Copilot AI Apr 18, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This switches the token generation input to client-id and references a new vars.CLIENT_ID. The workflow will fail at runtime unless CLIENT_ID is configured as a repository or environment variable (for the Release environment). Ensure the repo/env configuration is updated accordingly, and remove any now-unused APP_ID variable/secret to avoid confusion.

Copilot uses AI. Check for mistakes.
uses: actions/create-github-app-token@1b10c78c7865c340bc4f6099eb2f838309f1e8c3 # v3.1.1
with:
app-id: ${{ secrets.APP_ID }}
client-id: ${{ vars.CLIENT_ID }}

Copilot AI Apr 18, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This changes from ${{ secrets.APP_ID }} to ${{ vars.CLIENT_ID }}. Unless CLIENT_ID is defined as a repository variable or an environment variable for the CI-Checker environment, this step will fail. Please ensure the Actions variables/secrets are updated (and consider cleaning up the old APP_ID secret if it’s no longer used).

Suggested change
client-id: ${{ vars.CLIENT_ID }}
client-id: ${{ secrets.APP_ID }}

Copilot uses AI. Check for mistakes.
@5ouma 5ouma Bot mentioned this pull request Apr 18, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

🎽 CI Changes to CI configuration files and scripts

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants