Create GitHub releases with the workflow's own token instead of GH_RELEASE_PAT - #227
Merged
Merged
Conversation
…H_RELEASE_PAT The personal access token behind GH_RELEASE_PAT stopped working (401), so the v0.9.6 release reached PyPI but not GitHub. The release job only reads the released PRs and creates the GitHub release, which the workflow token can do with contents: write and pull-requests: read. It cannot expire, and no workflow listens for release events, so nothing depends on the release triggering one. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019heS4SVj8UqZ8BiMqDvoXj Signed-off-by: F.N. Claessen <claessen@seita.nl>
Coverage Report for CI Build 35138884105Coverage remained the same at 96.831%Details
Uncovered ChangesNo uncovered changes found. Coverage RegressionsNo coverage regressions found. Coverage Stats
💛 - Coveralls |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
The v0.9.6 release reached PyPI, but its
github-releasejob failed while generating the release notes:(run)
The job authenticates with the
GH_RELEASE_PATsecret. That worked for v0.9.5 on 2026-08-09, so the personal access token behind it has expired or been revoked since.I created the v0.9.6 GitHub release by hand.
Change
In the
github-releasejob, use${{ github.token }}instead ofsecrets.GH_RELEASE_PAT, for both the notes script andsoftprops/action-gh-release.The job gets its own
permissionsblock:contents: writeto create the release;pull-requests: readto read the titles, labels and authors of the released PRs.The block is needed because the workflow-level
permissions: contents: writeleaves every other scope atnone.This is how the HA integration's release workflow already works.
What we give up
A release created with the workflow token doesn't trigger other workflows.
No workflow in this repo runs on release events:
ci.ymlruns on push, andrelease.ymlitself on tag push. So nothing depends on that.Checks
main, so this change adds none.They're about the backslashes in the tag filter patterns and the undefined
inputs.custom_version, both outside this change.If it passes, the
GH_RELEASE_PATrepo secret can be deleted, and whoever created the token can revoke it.🤖 Generated with Claude Code
https://claude.ai/code/session_019heS4SVj8UqZ8BiMqDvoXj