Skip to content

docs(affirmation): affirm Roadmap Sync runs on a GitHub App token, no PAT - #910

Merged
hyperpolymath merged 1 commit into
mainfrom
affirmation/roadmap-sync-app-token
Oct 7, 2026
Merged

hyperpolymath merged 1 commit into
mainfrom
affirmation/roadmap-sync-app-token

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Summary

Adds one dated claim to AFFIRMATION.adoc under We affirm: Roadmap Sync runs on a ≤1 h GitHub App installation token (App hyperpolymath-roadmap-sync), with no personal access token. It writes to the org project metadatastician/projects/2. The legacy secret ADD_TO_PROJECT_PAT is no longer read by any workflow and will be deleted once the #35 → #2 item migration completes.

Why: #903 (fabe659) changed the credential, and the affirmation did not say so. The owner asked on 2026-10-07 for the affirmation of every repo touched by that work to be brought current.

Closes: no tracking issue (follow-up to #903).

Type of change

  • 🐛 Bug fix (non-breaking change that fixes an issue)
  • ✨ New feature (non-breaking change that adds functionality)
  • 💥 Breaking change (would change existing behaviour)
  • 🕳️ Soundness fix (fixes a checker/proof false-negative)
  • 📖 Documentation
  • 🧹 Refactor / tech debt (behaviour-preserving)
  • ⚡ Performance
  • 🔧 Build / CI / tooling

📌 New pins

  • Head SHA: 654ef0c40a6f4cb56a7ac54c979e0ee2441c4f25
  • None: this PR adds or changes no action pin, actions.lock entry, lockfile record or container digest.

How has this been verified?

Each sentence of the new bullet was checked against main at 1f30497:

  1. grep -n -E 'create-github-app-token|ROADMAP_SYNC|PROJECT_OWNER:|PROJECT_NUMBER:' .github/workflows/roadmap-sync.yml → the mint step uses actions/create-github-app-token@v3.2.0 with vars.ROADMAP_SYNC_APP_CLIENT_ID and secrets.ROADMAP_SYNC_APP_PRIVATE_KEY; PROJECT_OWNER: metadatastician, PROJECT_NUMBER: '2'.
  2. "No longer read by any workflow": grep -rn ADD_TO_PROJECT_PAT .github → no match (rc 1). Positive control: grep -rln 'secrets\.' .github/workflows → 14 files, so the grep does reach workflow files.
  3. "Remains stored": gh api repos/hyperpolymath/hypatia/actions/secrets lists ADD_TO_PROJECT_PAT and ROADMAP_SYNC_APP_PRIVATE_KEY.
  4. "Every scheduled run green since ci(roadmap-sync): mint a GitHub App token and sync into the metadatastician org project #903": gh run list -w roadmap-sync.yml showed event=schedule success on fabe659 (6 runs, 10-06 14:04Z→16:38Z) and on 1f30497 through 2026-10-07T09:05Z.
  5. git log -1 --format=%G? → G.

Checklist

  • My commits are signed (git commit -S). 654ef0c verifies G.
  • I ran the project's own checks/tests locally and they pass. Not applicable: a prose-only change to AFFIRMATION.adoc. No code, test or workflow is touched, and the required checks run in CI.
  • New files carry the correct SPDX-License-Identifier. No new files; AFFIRMATION.adoc keeps its CC-BY-SA-4.0 header.
  • Docs are updated, and no public claim now overstates what the code does. The claim is dated and scoped to 1f30497, and it states that the old secret is still stored.
  • I have not introduced a soundness hole. Prose only.

Notes for reviewers

  • :affirmed-at: is deliberately unchanged. Only this bullet is re-affirmed, inline-dated as the 2026-09-26 trusted-base re-measurement is. Moving the header date would assert that every other claim was re-verified.
  • When ADD_TO_PROJECT_PAT is deleted (Phase 5 of the migration), the last sentence of the bullet should be shortened accordingly.

🤖 Generated with Claude Code

https://claude.ai/code/session_011qEporYjgWy2Kw6WDQismf

@coderabbitai

coderabbitai Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 8af4cfbb-171e-4a9e-9506-808631bafb44
📥 Commits

Reviewing files that changed from the base of the PR and between 1f30497 and 654ef0c.

📒 Files selected for processing (1)
  • AFFIRMATION.adoc
 _______________________
< R2-D2 is my co-pilot. >
 -----------------------
  \
   \   \
        \ /\
        ( )
      .( o ).
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@hyperpolymath
hyperpolymath merged commit 10fff81 into main Oct 7, 2026
72 of 73 checks passed
@hyperpolymath
hyperpolymath deleted the affirmation/roadmap-sync-app-token branch October 7, 2026 10:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant