Skip to content

Create GitHub releases with the workflow's own token instead of GH_RELEASE_PAT - #227

Merged
Flix6x merged 1 commit into
mainfrom
ci/release-with-github-token
Sep 16, 2026
Merged

Flix6x merged 1 commit into
mainfrom
ci/release-with-github-token

Conversation

@Flix6x

@Flix6x Flix6x commented Sep 16, 2026

Copy link
Copy Markdown
Member

Problem

The v0.9.6 release reached PyPI, but its github-release job failed while generating the release notes:

urllib.error.HTTPError: HTTP Error 401: Unauthorized

(run)
The job authenticates with the GH_RELEASE_PAT secret. That worked for v0.9.5 on 2026-08-09, so the personal access token behind it has expired or been revoked since.
I created the v0.9.6 GitHub release by hand.

Change

In the github-release job, use ${{ github.token }} instead of secrets.GH_RELEASE_PAT, for both the notes script and softprops/action-gh-release.
The job gets its own permissions block:

  • contents: write to create the release;
  • pull-requests: read to read the titles, labels and authors of the released PRs.

The block is needed because the workflow-level permissions: contents: write leaves every other scope at none.

This is how the HA integration's release workflow already works.

What we give up

A release created with the workflow token doesn't trigger other workflows.
No workflow in this repo runs on release events: ci.yml runs on push, and release.yml itself on tag push. So nothing depends on that.

Checks

  • actionlint reports the same 7 findings on this branch as on main, so this change adds none.
    They're about the backslashes in the tag filter patterns and the undefined inputs.custom_version, both outside this change.
  • The job only runs on a tag push, so the next release is the real test.
    If it passes, the GH_RELEASE_PAT repo secret can be deleted, and whoever created the token can revoke it.

🤖 Generated with Claude Code

https://claude.ai/code/session_019heS4SVj8UqZ8BiMqDvoXj

…H_RELEASE_PAT

The personal access token behind GH_RELEASE_PAT stopped working (401), so the v0.9.6 release reached PyPI but not GitHub.
The release job only reads the released PRs and creates the GitHub release, which the workflow token can do with contents: write and pull-requests: read.
It cannot expire, and no workflow listens for release events, so nothing depends on the release triggering one.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019heS4SVj8UqZ8BiMqDvoXj
Signed-off-by: F.N. Claessen <claessen@seita.nl>
@coveralls

Copy link
Copy Markdown

Coverage Report for CI Build 35138884105

Coverage remained the same at 96.831%

Details

  • Coverage remained the same as the base build.
  • Patch coverage: No coverable lines changed in this PR.
  • No coverage regressions found.

Uncovered Changes

No uncovered changes found.

Coverage Regressions

No coverage regressions found.


Coverage Stats

Coverage Status
Relevant Lines: 852
Covered Lines: 825
Line Coverage: 96.83%
Coverage Strength: 9.68 hits per line

💛 - Coveralls

@Flix6x Flix6x self-assigned this Sep 16, 2026
@Flix6x
Flix6x merged commit 504883a into main Sep 16, 2026
17 checks passed
@Flix6x
Flix6x deleted the ci/release-with-github-token branch September 16, 2026 20:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants