Skip to content

Release from a protected environment and push the README with a GitHub App - #24

Merged
lhotari merged 1 commit into
mainfrom
release-environment-and-app-token
Sep 24, 2026
Merged

lhotari merged 1 commit into
mainfrom
release-environment-and-app-token

Conversation

@lhotari

@lhotari lhotari commented Sep 24, 2026

Copy link
Copy Markdown
Collaborator

Summary

  • publish uses environment: release. The Maven Central and signing secrets now live in that environment, which admits only v* tags and requires a maintainer's approval.
  • update-readme uses the same environment. It gets a short-lived token from actions/create-github-app-token@v3 (the RELEASE_APP_CLIENT_ID organization secret and the RELEASE_APP_PRIVATE_KEY environment secret), and that token can only write repository contents. The job checks out and pushes the README update with it, commits as <app-slug>[bot], and no longer needs contents: write on GITHUB_TOKEN. The release app can be on the main branch ruleset's bypass list, and its push triggers CI on the README commit.
  • RELEASING.md documents the release environment, its secrets, the release app, and GRADLE_ENCRYPTION_KEY.
  • .github/actionlint.yaml ignores two actionlint errors about create-github-app-token in release.yml. actionlint 1.7.12's bundled metadata for that action is older than its client-id input.

Setup this depends on

  • The release GitHub App is installed on jonoffcpu/jonoffcpu and has the Contents read and write permission.
  • The app is on the bypass list of the main ruleset when the ruleset is active.
  • The release environment holds MAVEN_CENTRAL_USERNAME, MAVEN_CENTRAL_PASSWORD, SIGNING_IN_MEMORY_KEY, SIGNING_IN_MEMORY_KEY_ID, SIGNING_IN_MEMORY_KEY_PASSWORD and RELEASE_APP_PRIVATE_KEY, and no repository or organization copies of these remain.

Each release waits for two approvals, one for publish and one for update-readme.

Verification

  • actionlint 1.7.12 (local and the pinned Docker image) and zizmor 1.30.1 with online audits pass.
  • The environment and the app token are only exercised by the next v* tag.

…b App

The publish job now reads the Maven Central and signing secrets from the
protected `release` environment, which admits only v* tags and waits
for a maintainer's approval, so no other workflow, branch or job can
read them.

The README version update is pushed with a short-lived token of the
release GitHub App instead of GITHUB_TOKEN: the app is on the bypass
list of the main branch ruleset, the token can only write repository
contents, and its push triggers CI on the README commit. The job reads
the app's private key from the same environment, commits as the app's
bot user and no longer needs contents: write on GITHUB_TOKEN.

RELEASING.md describes the environment, its secrets and the release
app. actionlint's bundled metadata of create-github-app-token predates
its client-id input, so the two resulting errors are ignored for the
release workflow.
@lhotari lhotari added the maintenance Build, CI, dependency and other maintenance changes label Sep 24, 2026
@lhotari
lhotari merged commit 0ed19cf into main Sep 24, 2026
7 checks passed
@lhotari
lhotari deleted the release-environment-and-app-token branch September 24, 2026 14:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

maintenance Build, CI, dependency and other maintenance changes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant