Skip to content

fix(ci): mint the App token from the client ID, not the app ID - #2

Merged
catinspace-au merged 1 commit into
mainfrom
fix/app-token-client-id
Aug 5, 2026
Merged

catinspace-au merged 1 commit into
mainfrom
fix/app-token-client-id

Conversation

@catinspace-au

Copy link
Copy Markdown
Contributor

Every run in this repo currently logs a deprecation warning, because
actions/create-github-app-token deprecated its app-id input in v3.2.0 in
favour of client-id.

Being precise about what is deprecated, because the loose version keeps getting
repeated: the numeric App ID is NOT deprecated at the platform level and still
works. The INPUT is. GitHub separately recommends the client ID because
compatibility with future App APIs depends on it - the app ID is not globally
unique and the app name is not immutable.

HOMEBREW_APP_CLIENT_ID is an org VARIABLE, not a secret. A client ID is not sensitive, and
putting it in secrets only makes a log harder to read. It was derived from the
same app's private key by hyperi-infra scripts/github-app-client-ids.py, so it
pairs with HOMEBREW_APP_PRIVATE_KEY by construction rather than by coincidence.

The action ref also moves from the floating @v1 tag to a SHA-pinned v3.2.0,
and it has to move in the same commit: client-id does not exist before v3, so
changing the input alone would break the token mint rather than fix a warning.
v3.2.0 drops only the legacy snake_case aliases (app_id, private_key,
skip_token_revoke), none of which this repo uses.

Done when a run log shows no app-id deprecation warning.

Part of a fleet sweep - hyperi-io/hyperi-ci#100.

actions/create-github-app-token deprecated its `app-id` input in v3.2.0 in
favour of `client-id`, so every run using it logs a deprecation warning.

The numeric App ID is NOT deprecated at the platform level - the INPUT is.
GitHub recommends the client ID because compatibility with future App APIs
depends on it: the app ID is not globally unique and the app name is not
immutable.

The action ref moves from the floating `@v1` tag to a SHA-pinned v3.2.0 in the
same commit, because it has to: `client-id` does not exist before v3, so
swapping the input alone would break the mint. v3.2.0 removes only the legacy
snake_case aliases (`app_id`, `private_key`, `skip_token_revoke`), none of
which are used here.

`HOMEBREW_APP_CLIENT_ID` is an org VARIABLE, not a secret - a client ID is not sensitive, and
putting it in secrets only makes a log harder to read. It was derived from the
same app's private key by hyperi-infra scripts/github-app-client-ids.py, so it
pairs with `HOMEBREW_APP_PRIVATE_KEY` by construction.

Refs hyperi-io/hyperi-ci#100
@catinspace-au
catinspace-au merged commit 768f3cc into main Aug 5, 2026
8 of 9 checks passed
@catinspace-au
catinspace-au deleted the fix/app-token-client-id branch August 5, 2026 03:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant