From 4922ccf11fc362faa8e564f7eda2a38aa0bb80f1 Mon Sep 17 00:00:00 2001 From: Derek Date: Wed, 5 Aug 2026 13:13:50 +1000 Subject: [PATCH] fix(ci): mint the App token from the client ID, not the app ID actions/create-github-app-token deprecated its `app-id` input in v3.2.0 in favour of `client-id`, so every run using it logs a deprecation warning. The numeric App ID is NOT deprecated at the platform level - the INPUT is. GitHub recommends the client ID because compatibility with future App APIs depends on it: the app ID is not globally unique and the app name is not immutable. The action ref moves from the floating `@v1` tag to a SHA-pinned v3.2.0 in the same commit, because it has to: `client-id` does not exist before v3, so swapping the input alone would break the mint. v3.2.0 removes only the legacy snake_case aliases (`app_id`, `private_key`, `skip_token_revoke`), none of which are used here. `HOMEBREW_APP_CLIENT_ID` is an org VARIABLE, not a secret - a client ID is not sensitive, and putting it in secrets only makes a log harder to read. It was derived from the same app's private key by hyperi-infra scripts/github-app-client-ids.py, so it pairs with `HOMEBREW_APP_PRIVATE_KEY` by construction. Refs hyperi-io/hyperi-ci#100 --- .github/workflows/release.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index d836bf8..cec5a7d 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -266,9 +266,9 @@ jobs: steps.version.outputs.release_needed == 'true' && env.HOMEBREW_APP_ID != '' id: app-token - uses: actions/create-github-app-token@v1 + uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0 with: - app-id: ${{ secrets.HOMEBREW_APP_ID }} + client-id: ${{ vars.HOMEBREW_APP_CLIENT_ID }} private-key: ${{ secrets.HOMEBREW_APP_PRIVATE_KEY }} owner: hyperi-io repositories: homebrew-git-scrub