From 654ef0c40a6f4cb56a7ac54c979e0ee2441c4f25 Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Wed, 7 Oct 2026 11:16:10 +0100 Subject: [PATCH] docs(affirmation): affirm Roadmap Sync runs on a GitHub App token, no PAT Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_011qEporYjgWy2Kw6WDQismf --- AFFIRMATION.adoc | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/AFFIRMATION.adoc b/AFFIRMATION.adoc index aef7547a..1b0b9826 100644 --- a/AFFIRMATION.adoc +++ b/AFFIRMATION.adoc @@ -43,6 +43,15 @@ state and commitments. Companion detail: * *Workflow hygiene.* Every runner job declares `timeout-minutes`; the `workflow_audit` rule no longer false-positives reusable-workflow (`uses:`) jobs. +* *Roadmap Sync uses no personal access token* (affirmed 2026-10-07 at + `1f30497`). `.github/workflows/roadmap-sync.yml` mints a ≤1 h installation + token of the GitHub App `hyperpolymath-roadmap-sync` per run + (`actions/create-github-app-token`, client id variable + `ROADMAP_SYNC_APP_CLIENT_ID`, key secret `ROADMAP_SYNC_APP_PRIVATE_KEY`) and + writes to the org project `metadatastician/projects/2`. Every scheduled run + has been green since #903 (`fabe659`). The old secret `ADD_TO_PROJECT_PAT` is + no longer read by any workflow. It remains stored until the item migration + from the user project #35 completes, and is then deleted. * *SPDX `MPL-2.0` headers* on source files; SHA-pinned GitHub Actions; HTTPS-only; no hardcoded secrets.