Skip to content

chore(runway): cherry-pick ci: Update add-team-label and check-template-and-add-labels workflows to use OIDC token exchange cp-7.80.0#30870

Merged
runway-github[bot] merged 1 commit into
release/7.80.0from
runway-cherry-pick-7.80.0-1780325157
Jun 1, 2026
Merged

chore(runway): cherry-pick ci: Update add-team-label and check-template-and-add-labels workflows to use OIDC token exchange cp-7.80.0#30870
runway-github[bot] merged 1 commit into
release/7.80.0from
runway-cherry-pick-7.80.0-1780325157

Conversation

@runway-github

@runway-github runway-github Bot commented Jun 1, 2026

Copy link
Copy Markdown
Contributor

Description

This updates the add-team-label and check-template-and-add-labels
workflows to use OIDC token exchange.

Changelog

CHANGELOG entry:

Related issues

Fixes:

Manual testing steps

Feature: my feature name

  Scenario: user [verb for user action]
    Given [describe expected initial app state]

    When user [verb for user action]
    Then [describe expected outcome]

Screenshots/Recordings

Before

After

Pre-merge author checklist

Performance checks (if applicable)

  • I've tested on Android
    • Ideally on a mid-range device; emulator is acceptable
  • I've tested with a power user scenario
  • Use these power-user
    SRPs

    to import wallets with many accounts and tokens
  • I've instrumented key operations with Sentry traces for production
    performance metrics
  • See trace() for usage and
    addToken
    for an example

For performance guidelines and tooling, see the Performance
Guide
.

Pre-merge reviewer checklist

  • I've manually tested the PR (e.g. pull and build branch, run the
    app, test code being changed).
  • I confirm that this PR addresses all acceptance criteria described
    in the ticket it closes and includes the necessary testing evidence such
    as recordings and or screenshots.

Note

Medium Risk
Changes how automation authenticates to GitHub (and planning);
misconfiguration could break PR/issue labeling until tokens and
permissions are correct.

Overview
Two GitHub Actions workflows now obtain GitHub API tokens through
OIDC token exchange (MetaMask/github-tools get-token@v1 and
vars.TOKEN_EXCHANGE_URL) instead of repository secrets
(TEAM_LABEL_TOKEN, LABEL_TOKEN).

add-team-label grants id-token: write, mints a read-only token
for MetaMask/MetaMask-planning, a separate token with pull_requests: write, and passes both into add-team-label@v1 as planning-token and
team-label-token.

check-template-and-add-labels adds contents: read and
id-token: write, fetches a scoped token (issues: write, members: read, pull_requests: write), and wires LABEL_TOKEN to that output
for the existing script step.

Reviewed by Cursor Bugbot for commit
b51e09a. Bugbot is set up for automated
code reviews on this repo. Configure
here.

[14486dc](https://github.com/MetaMask/metamask-mobile/commit/14486dced7594887494d48827a3363eef8099069)

…plate-and-add-labels` workflows to use OIDC token exchange cp-7.80.0 (#30840)

<!--
Please submit this PR as a draft initially.

Do not mark it as "Ready for review" until this PR meets the canonical
Definition of Ready For Review in `docs/readme/ready-for-review.md`.

In short: the template must be materially complete (not just section
titles
present), all status checks must be currently passing, and the only
expected
follow-up commits must be reviewer-driven.
-->

## **Description**

This updates the `add-team-label` and `check-template-and-add-labels`
workflows to use OIDC token exchange.

## **Changelog**

<!--
If this PR is not End-User-Facing and should not show up in the
CHANGELOG, you can choose to either:
1. Write `CHANGELOG entry: null`
2. Label with `no-changelog`

If this PR is End-User-Facing, please write a short User-Facing
description in the past tense like:
`CHANGELOG entry: Added a new tab for users to see their NFTs`
`CHANGELOG entry: Fixed a bug that was causing some NFTs to flicker`

(This helps the Release Engineer do their job more quickly and
accurately)
-->

CHANGELOG entry:

## **Related issues**

Fixes:

## **Manual testing steps**

```gherkin
Feature: my feature name

  Scenario: user [verb for user action]
    Given [describe expected initial app state]

    When user [verb for user action]
    Then [describe expected outcome]
```

## **Screenshots/Recordings**

<!-- If applicable, add screenshots and/or recordings to visualize the
before and after of your change. -->

### **Before**

<!-- [screenshots/recordings] -->

### **After**

<!-- [screenshots/recordings] -->

## **Pre-merge author checklist**

<!--
Every checklist item must be consciously assessed before marking this PR
as
"Ready for review". A checked box means you deliberately considered that
responsibility, not that you literally performed every action listed.

Unchecked boxes are ambiguous: they are not an implicit "N/A" and they
are not
a silent "skip". See `docs/readme/ready-for-review.md` for the full
checklist
semantics.
-->

- [ ] I've followed [MetaMask Contributor
Docs](https://github.com/MetaMask/contributor-docs) and [MetaMask Mobile
Coding
Standards](https://github.com/MetaMask/metamask-mobile/blob/main/.github/guidelines/CODING_GUIDELINES.md).
- [ ] I've completed the PR template to the best of my ability
- [ ] I've included tests if applicable
- [ ] I've documented my code using [JSDoc](https://jsdoc.app/) format
if applicable
- [ ] I've applied the right labels on the PR (see [labeling
guidelines](https://github.com/MetaMask/metamask-mobile/blob/main/.github/guidelines/LABELING_GUIDELINES.md)).
Not required for external contributors.

#### Performance checks (if applicable)

- [ ] I've tested on Android
  - Ideally on a mid-range device; emulator is acceptable
- [ ] I've tested with a power user scenario
- Use these [power-user
SRPs](https://consensyssoftware.atlassian.net/wiki/spaces/TL1/pages/edit-v2/401401446401?draftShareId=9d77e1e1-4bdc-4be1-9ebb-ccd916988d93)
to import wallets with many accounts and tokens
- [ ] I've instrumented key operations with Sentry traces for production
performance metrics
- See [`trace()`](/app/util/trace.ts) for usage and
[`addToken`](/app/components/Views/AddAsset/components/AddCustomToken/AddCustomToken.tsx#L274)
for an example

For performance guidelines and tooling, see the [Performance
Guide](https://consensyssoftware.atlassian.net/wiki/spaces/TL1/pages/400085549067/Performance+Guide+for+Engineers).

## **Pre-merge reviewer checklist**

<!--
Reviewer checklist items follow the same semantics as the author
checklist: an
unchecked box is ambiguous, a checked box means the reviewer consciously
assessed that responsibility. See `docs/readme/ready-for-review.md`.
-->

- [ ] I've manually tested the PR (e.g. pull and build branch, run the
app, test code being changed).
- [ ] I confirm that this PR addresses all acceptance criteria described
in the ticket it closes and includes the necessary testing evidence such
as recordings and or screenshots.

<!-- CURSOR_SUMMARY -->
---

> [!NOTE]
> **Medium Risk**
> Changes how automation authenticates to GitHub (and planning);
misconfiguration could break PR/issue labeling until tokens and
permissions are correct.
> 
> **Overview**
> Two GitHub Actions workflows now obtain GitHub API tokens through
**OIDC token exchange** (`MetaMask/github-tools` `get-token@v1` and
`vars.TOKEN_EXCHANGE_URL`) instead of repository **secrets**
(`TEAM_LABEL_TOKEN`, `LABEL_TOKEN`).
> 
> **`add-team-label`** grants `id-token: write`, mints a read-only token
for `MetaMask/MetaMask-planning`, a separate token with `pull_requests:
write`, and passes both into `add-team-label@v1` as `planning-token` and
`team-label-token`.
> 
> **`check-template-and-add-labels`** adds `contents: read` and
`id-token: write`, fetches a scoped token (`issues: write`, `members:
read`, `pull_requests: write`), and wires `LABEL_TOKEN` to that output
for the existing script step.
> 
> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit
b51e09a. Bugbot is set up for automated
code reviews on this repo. Configure
[here](https://www.cursor.com/dashboard/bugbot).</sup>
<!-- /CURSOR_SUMMARY -->
@runway-github runway-github Bot requested a review from a team as a code owner June 1, 2026 14:46
@mm-token-exchange-service mm-token-exchange-service Bot added the team-bots Bot team (for MetaMask Bot, Runway Bot, etc.) label Jun 1, 2026
@github-actions github-actions Bot added the size-S label Jun 1, 2026
@runway-github runway-github Bot merged commit 8ec8107 into release/7.80.0 Jun 1, 2026
152 of 155 checks passed
@runway-github runway-github Bot deleted the runway-cherry-pick-7.80.0-1780325157 branch June 1, 2026 15:24
@github-actions github-actions Bot locked and limited conversation to collaborators Jun 1, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

size-S team-bots Bot team (for MetaMask Bot, Runway Bot, etc.)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants