fix(ci): open release-please PRs as its-miso bot - #108
Conversation
Release PRs created with the default GITHUB_TOKEN are authored by github-actions[bot], and pushes with that token do not trigger pull_request workflows: required checks on PR #57 report action_required with no retrievable logs, leaving the release unmergeable since 2026-08-26. Generate the MISO app token and pass it to release-please, matching pr-reviewer-action and alert-triage. The AI PR review still runs on the release PR; nothing is bypassed.
There was a problem hiding this comment.
AI Automated Review
Full PR review.
Analysis engine: MiniMax-M2.7@https://litellm.jory.dev/v1 (anthropic) — primary route
Recommendation: Approve
This is a targeted, well-explained CI fix that solves the exact problem described in the PR body: release-please PRs authored by github-actions[bot] with the default GITHUB_TOKEN don't trigger pull_request workflow runs, causing required checks to land as action_required with no logs. The fix generates a MISO GitHub App token and passes it to release-please, matching the pattern already used by pr-reviewer-action and alert-triage in this repository.
Change-by-Change Findings
.github/workflows/release-please.yml (+13 lines)
- New step — "Generate bot token" (
actions/create-github-app-token@v3.2.0, SHA-pinned): Generates a short-lived GitHub App token usingMISO_APP_IDandMISO_APP_PRIVATE_KEYfrom secrets. This is the same pattern used by the other MISO automation workflows referenced in the PR body. - Updated step — "release": Passes
steps.app-token.outputs.tokento the release-please action'stokeninput.
Both action versions are SHA-pinned (correct anti-tampering practice). The comment block explains the why clearly.
Standards Compliance
- Action pinning: Both
actions/create-github-app-tokenandgoogleapis/release-please-actionuse full commit SHAs rather than tags, satisfying the implicit security expectation for GitHub Actions in this repo's workflow files. - Secret handling: Secrets are referenced via
${{ secrets.* }}and used only to generate a scoped token, not passed directly to external commands — appropriate pattern. - No repository standards file applies — AGENTS.md covers application code; CI workflow changes are not governed by the Elixir/JS formatting/linting gates.
CI Gate
All three required checks passed at the commit under review:
| Check | State |
|---|---|
| Build RC Image | ✅ success |
| Build PR Image | ✅ success |
| Lint and Test | ✅ success |
Unknowns / Needs Verification
None. The diff is self-contained, CI is green, and the approach matches existing MISO workflow patterns.
|
🐳 Image for commit 1a929fa published: |
Release-please was running with the default
GITHUB_TOKEN, so PR #57 is authored byapp/github-actionsand its branch pushes never triggerpull_requestworkflows — the required CI/AI-review checks land asaction_requiredwith no logs, which is why the release has been stuck since 2026-08-26 with 11+ merged fixes (several security) bottled up behind it.This generates the MISO app token and passes it to release-please, matching
pr-reviewer-actionandalert-triage. The release PR then goes through CI and the AI PR reviewer like any other PR — the reviewer is not bypassed.After this merges, the next release-please run pushes to #57's branch with the app token, which triggers the checks on the existing PR — no need to close and reopen it.
Refs #106 (which diagnosed this as the reviewer gating release PRs; the actual cause is token identity).