Skip to content

Use GitHub App token instead of default token#252

Merged
5ouma merged 1 commit intomainfrom
ci-release-app-token
Jun 14, 2025
Merged

Use GitHub App token instead of default token#252
5ouma merged 1 commit intomainfrom
ci-release-app-token

Conversation

@5ouma
Copy link
Owner

@5ouma 5ouma commented Jun 14, 2025

⚠️ Issue

close #


✏️ Description

It will fire workflows that can't be with the default token.


Copilot AI review requested due to automatic review settings June 14, 2025 12:05
@github-actions github-actions bot added the 🎽 CI Changes to CI configuration files and scripts label Jun 14, 2025
Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR replaces the default GITHUB_TOKEN with a GitHub App token so workflows can be triggered with elevated permissions.

  • Removes job-level contents: write and pull-requests: write permissions on the default token.
  • Adds a step to generate a GitHub App token with the necessary scopes.
  • Updates the tagpr action to use the newly generated token.
Comments suppressed due to low confidence (2)

.github/workflows/release.yml:23

  • The Create GitHub App Token step runs after checkout, so the checkout step still uses the default GITHUB_TOKEN. Consider moving the token creation before checkout or re-running actions/checkout with token: ${{ steps.app-token.outputs.token }} to ensure the correct credentials are used.
persist-credentials: true

.github/workflows/release.yml:27

  • [nitpick] Pinning to a hard-coded commit SHA can make future upgrades harder. Consider using a version tag (e.g., @v2 or @v2.0.6) to simplify maintenance and get patch updates automatically.
uses: actions/create-github-app-token@df432ceedc7162793a195dd1713ff69aefc7379e # v2.0.6

It will fire workflows which can't be with the default token.
@coderabbitai
Copy link

coderabbitai bot commented Jun 14, 2025

Warning

Rate limit exceeded

@5ouma has exceeded the limit for the number of commits or files that can be reviewed per hour. Please wait 14 minutes and 34 seconds before requesting another review.

⌛ How to resolve this issue?

After the wait time has elapsed, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

We recommend that you space out your commits to avoid hitting the rate limit.

🚦 How do rate limits work?

CodeRabbit enforces hourly rate limits for each developer per organization.

Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout.

Please see our FAQ for further information.

📥 Commits

Reviewing files that changed from the base of the PR and between 017216e and e26991b.

📒 Files selected for processing (2)
  • .github/ghalint.yml (0 hunks)
  • .github/workflows/release.yml (1 hunks)

Walkthrough

The changes remove a GitHub Actions lint exclusion configuration and update the release workflow. The workflow now replaces the default repository token with a GitHub App token for tagging releases, disables checkout persistent credentials, and removes explicit job permissions for the tag creation step.

Changes

Files/Groups Change Summary
.github/ghalint.yml Deleted configuration excluding a specific lint policy violation for the release workflow's tagpr job.
.github/workflows/release.yml Removed explicit job permissions, disabled checkout persistent credentials, added GitHub App token generation and usage for release tagging.
✨ Finishing Touches
🧪 Generate Unit Tests
  • Create PR with Unit Tests
  • Commit Unit Tests in branch ci-release-app-token
  • Post Copyable Unit Tests in Comment

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share
🪧 Tips

Chat

There are 3 ways to chat with CodeRabbit:

  • Review comments: Directly reply to a review comment made by CodeRabbit. Example:
    • I pushed a fix in commit <commit_id>, please review it.
    • Explain this complex logic.
    • Open a follow-up GitHub issue for this discussion.
  • Files and specific lines of code (under the "Files changed" tab): Tag @coderabbitai in a new review comment at the desired location with your query. Examples:
    • @coderabbitai explain this code block.
    • @coderabbitai modularize this function.
  • PR comments: Tag @coderabbitai in a new PR comment to ask questions about the PR branch. For the best results, please provide a very specific query, as very limited context is provided in this mode. Examples:
    • @coderabbitai gather interesting stats about this repository and render them as a table. Additionally, render a pie chart showing the language distribution in the codebase.
    • @coderabbitai read src/utils.ts and explain its main purpose.
    • @coderabbitai read the files in the src/scheduler package and generate a class diagram using mermaid and a README in the markdown format.
    • @coderabbitai help me debug CodeRabbit configuration file.

Support

Need help? Create a ticket on our support page for assistance with any issues or questions.

Note: Be mindful of the bot's finite context window. It's strongly recommended to break down tasks such as reading entire modules into smaller chunks. For a focused discussion, use review comments to chat about specific files and their changes, instead of using the PR comments.

CodeRabbit Commands (Invoked using PR comments)

  • @coderabbitai pause to pause the reviews on a PR.
  • @coderabbitai resume to resume the paused reviews.
  • @coderabbitai review to trigger an incremental review. This is useful when automatic reviews are disabled for the repository.
  • @coderabbitai full review to do a full review from scratch and review all the files again.
  • @coderabbitai summary to regenerate the summary of the PR.
  • @coderabbitai generate docstrings to generate docstrings for this PR.
  • @coderabbitai generate sequence diagram to generate a sequence diagram of the changes in this PR.
  • @coderabbitai auto-generate unit tests to generate unit tests for this PR.
  • @coderabbitai resolve resolve all the CodeRabbit review comments.
  • @coderabbitai configuration to show the current CodeRabbit configuration for the repository.
  • @coderabbitai help to get help.

Other keywords and placeholders

  • Add @coderabbitai ignore anywhere in the PR description to prevent this PR from being reviewed.
  • Add @coderabbitai summary to generate the high-level summary at a specific location in the PR description.
  • Add @coderabbitai anywhere in the PR title to generate the title automatically.

CodeRabbit Configuration File (.coderabbit.yaml)

  • You can programmatically configure CodeRabbit by adding a .coderabbit.yaml file to the root of your repository.
  • Please see the configuration documentation for more information.
  • If your editor has YAML language server enabled, you can add the path at the top of this file to enable auto-completion and validation: # yaml-language-server: $schema=https://coderabbit.ai/integrations/schema.v2.json

Documentation and Community

  • Visit our Documentation for detailed information on how to use CodeRabbit.
  • Join our Discord Community to get help, request features, and share feedback.
  • Follow us on X/Twitter for updates and announcements.

@5ouma
Copy link
Owner Author

5ouma commented Jun 14, 2025

@coderabbitai review

@coderabbitai
Copy link

coderabbitai bot commented Jun 14, 2025

✅ Actions performed

Review triggered.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@5ouma 5ouma merged commit fa760d7 into main Jun 14, 2025
7 checks passed
@5ouma 5ouma deleted the ci-release-app-token branch June 14, 2025 12:15
@5ouma 5ouma bot mentioned this pull request Jun 14, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

🎽 CI Changes to CI configuration files and scripts

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants