From c58139723adf1499014faf5ceb4e65ac236ee07c Mon Sep 17 00:00:00 2001 From: Wolfgang Walther Date: Thu, 6 Nov 2025 12:11:00 +0100 Subject: [PATCH 1/2] workflows/pull-request-target: remove leftover secret This was used for reviewers.yml, which has been removed. --- .github/workflows/pull-request-target.yml | 3 --- 1 file changed, 3 deletions(-) diff --git a/.github/workflows/pull-request-target.yml b/.github/workflows/pull-request-target.yml index a3774366bc9b..f74ce93de354 100644 --- a/.github/workflows/pull-request-target.yml +++ b/.github/workflows/pull-request-target.yml @@ -12,9 +12,6 @@ on: required: true NIXPKGS_CI_APP_PRIVATE_KEY: required: true - OWNER_APP_PRIVATE_KEY: - # The Test workflow should not actually request reviews from owners. - required: false concurrency: group: pr-${{ github.workflow }}-${{ github.event_name }}-${{ github.event.pull_request.number || github.run_id }} From 1742aef1e988b884b81d6b6060be33d1b8dd1a41 Mon Sep 17 00:00:00 2001 From: Wolfgang Walther Date: Thu, 6 Nov 2025 12:11:34 +0100 Subject: [PATCH 2/2] workflows/teams: use single token in team sync The nixpkgs-ci app now has all the privileges needed to see the member lists anyway, so no need for two apps / tokens anymore. --- .github/workflows/teams.yml | 27 +++++++++++---------------- 1 file changed, 11 insertions(+), 16 deletions(-) diff --git a/.github/workflows/teams.yml b/.github/workflows/teams.yml index 1cd54cd527e0..b848983b5aa2 100644 --- a/.github/workflows/teams.yml +++ b/.github/workflows/teams.yml @@ -16,13 +16,17 @@ jobs: sync: runs-on: ubuntu-24.04-arm steps: + # Use a GitHub App to create the PR so that CI gets triggered and to + # request team member lists. - uses: actions/create-github-app-token@67018539274d69449ef7c02e8e71183d1719ab42 # v2.1.4 - id: team-token + id: app-token with: - app-id: ${{ vars.OWNER_APP_ID }} - private-key: ${{ secrets.OWNER_APP_PRIVATE_KEY }} + app-id: ${{ vars.NIXPKGS_CI_APP_ID }} + private-key: ${{ secrets.NIXPKGS_CI_APP_PRIVATE_KEY }} permission-administration: read + permission-contents: write permission-members: read + permission-pull-requests: write - name: Fetch source uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0 @@ -38,7 +42,7 @@ jobs: - name: Synchronise teams uses: actions/github-script@ed597411d8f924073f98dfc5c65a23a2325f34cd # v8.0.0 with: - github-token: ${{ steps.team-token.outputs.token }} + github-token: ${{ steps.app-token.outputs.token }} script: | require('./ci/github-script/get-teams.js')({ github, @@ -47,20 +51,11 @@ jobs: outFile: "maintainers/github-teams.json" }) - # Use a GitHub App to create the PR so that CI gets triggered - - uses: actions/create-github-app-token@67018539274d69449ef7c02e8e71183d1719ab42 # v2.1.4 - id: sync-token - with: - app-id: ${{ vars.NIXPKGS_CI_APP_ID }} - private-key: ${{ secrets.NIXPKGS_CI_APP_PRIVATE_KEY }} - permission-contents: write - permission-pull-requests: write - - name: Get GitHub App User Git String id: user env: - GH_TOKEN: ${{ steps.sync-token.outputs.token }} - APP_SLUG: ${{ steps.sync-token.outputs.app-slug }} + GH_TOKEN: ${{ steps.app-token.outputs.token }} + APP_SLUG: ${{ steps.app-token.outputs.app-slug }} run: | name="${APP_SLUG}[bot]" userId=$(gh api "/users/$name" --jq .id) @@ -70,7 +65,7 @@ jobs: - name: Create Pull Request uses: peter-evans/create-pull-request@271a8d0340265f705b14b6d32b9829c1cb33d45e # v7.0.8 with: - token: ${{ steps.sync-token.outputs.token }} + token: ${{ steps.app-token.outputs.token }} add-paths: maintainers/github-teams.json author: ${{ steps.user.outputs.git-string }} committer: ${{ steps.user.outputs.git-string }}