Skip to content

fix(ci): open release-please PRs as its-miso bot - #108

Merged
joryirving merged 1 commit into
mainfrom
fix/release-please-app-token
Sep 20, 2026
Merged

joryirving merged 1 commit into
mainfrom
fix/release-please-app-token

Conversation

@joryirving

Copy link
Copy Markdown
Contributor

Release-please was running with the default GITHUB_TOKEN, so PR #57 is authored by app/github-actions and its branch pushes never trigger pull_request workflows — the required CI/AI-review checks land as action_required with no logs, which is why the release has been stuck since 2026-08-26 with 11+ merged fixes (several security) bottled up behind it.

This generates the MISO app token and passes it to release-please, matching pr-reviewer-action and alert-triage. The release PR then goes through CI and the AI PR reviewer like any other PR — the reviewer is not bypassed.

After this merges, the next release-please run pushes to #57's branch with the app token, which triggers the checks on the existing PR — no need to close and reopen it.

Refs #106 (which diagnosed this as the reviewer gating release PRs; the actual cause is token identity).

Release PRs created with the default GITHUB_TOKEN are authored by
github-actions[bot], and pushes with that token do not trigger
pull_request workflows: required checks on PR #57 report
action_required with no retrievable logs, leaving the release
unmergeable since 2026-08-26.

Generate the MISO app token and pass it to release-please, matching
pr-reviewer-action and alert-triage. The AI PR review still runs on
the release PR; nothing is bypassed.

@its-saffron its-saffron Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI Automated Review

Full PR review.

Analysis engine: MiniMax-M2.7@https://litellm.jory.dev/v1 (anthropic) — primary route

Recommendation: Approve

This is a targeted, well-explained CI fix that solves the exact problem described in the PR body: release-please PRs authored by github-actions[bot] with the default GITHUB_TOKEN don't trigger pull_request workflow runs, causing required checks to land as action_required with no logs. The fix generates a MISO GitHub App token and passes it to release-please, matching the pattern already used by pr-reviewer-action and alert-triage in this repository.

Change-by-Change Findings

.github/workflows/release-please.yml (+13 lines)

  1. New step — "Generate bot token" (actions/create-github-app-token@v3.2.0, SHA-pinned): Generates a short-lived GitHub App token using MISO_APP_ID and MISO_APP_PRIVATE_KEY from secrets. This is the same pattern used by the other MISO automation workflows referenced in the PR body.
  2. Updated step — "release": Passes steps.app-token.outputs.token to the release-please action's token input.

Both action versions are SHA-pinned (correct anti-tampering practice). The comment block explains the why clearly.

Standards Compliance

  • Action pinning: Both actions/create-github-app-token and googleapis/release-please-action use full commit SHAs rather than tags, satisfying the implicit security expectation for GitHub Actions in this repo's workflow files.
  • Secret handling: Secrets are referenced via ${{ secrets.* }} and used only to generate a scoped token, not passed directly to external commands — appropriate pattern.
  • No repository standards file applies — AGENTS.md covers application code; CI workflow changes are not governed by the Elixir/JS formatting/linting gates.

CI Gate

All three required checks passed at the commit under review:

Check State
Build RC Image ✅ success
Build PR Image ✅ success
Lint and Test ✅ success

Unknowns / Needs Verification

None. The diff is self-contained, CI is green, and the approach matches existing MISO workflow patterns.

@github-actions

Copy link
Copy Markdown
Contributor

🐳 Image for commit 1a929fa published: ghcr.io/misospace/pinchflat-dev:pr-108-1a929fa

@joryirving
joryirving merged commit 2ea0ff0 into main Sep 20, 2026
4 checks passed
@joryirving
joryirving deleted the fix/release-please-app-token branch September 20, 2026 02:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant