Skip to content

Use client-id for app token; upgrade checkout and setup-python to v7 - #19

Merged
arcivanov merged 1 commit into
masterfrom
use-app-token-client-id
Oct 7, 2026
Merged

arcivanov merged 1 commit into
masterfrom
use-app-token-client-id

Conversation

@arcivanov

@arcivanov arcivanov commented Oct 6, 2026 •

Copy link
Copy Markdown
Member

actions/create-github-app-token@v3 deprecated the app-id input in favor of client-id, which emits a deprecation warning on both the main and post steps of every release run. This passes release-app-id via client-id instead. The action treats both inputs identically (client-id || app-id, passed as appId to @octokit/auth-app), so existing numeric App IDs supplied via release-app-id continue to work unchanged. The release-app-id input name is kept for compatibility; its description now notes it accepts either the Client ID or the legacy App ID.

Also bumps actions/checkout to v7 (from v6 in action.yml, v5 in the test workflow) and actions/setup-python to v7 (from v6) in both action.yml and the test workflow, with README references updated accordingly. Notable upstream changes:

  • checkout v7: ESM migration and dependency bumps; refuses to check out fork PR code under pull_request_target/workflow_run unless allow-unsafe-pr-checkout is set. Callers of this action using those triggers would be affected, since the action performs the checkout for them.
  • setup-python v7: ESM migration, manifest fetch retry, stderr warnings classified as warnings; removes the pip-install input, which this action does not use.

All inputs this action passes (persist-credentials, python-version, architecture) remain present in v7.

create-github-app-token v3 deprecated the 'app-id' input in favor of
'client-id', emitting a warning on both the main and post steps. The
action treats both inputs identically (client-id || app-id, passed as
appId to @octokit/auth-app), so existing numeric App IDs supplied via
release-app-id continue to work unchanged.

Also bump actions/checkout to v7 (from v6 in action.yml, v5 in the
test workflow) and actions/setup-python to v7 (from v6) in both the
action and the test workflow, and update README references.
@arcivanov
arcivanov force-pushed the use-app-token-client-id branch from 560b849 to 95b2058 Compare October 6, 2026 20:52
@arcivanov arcivanov changed the title Pass release app ID via client-id to create-github-app-token Use client-id for app token; upgrade checkout and setup-python to v7 Oct 6, 2026
@arcivanov
arcivanov merged commit 32faa36 into master Oct 7, 2026
95 of 124 checks passed
@arcivanov
arcivanov deleted the use-app-token-client-id branch October 7, 2026 00:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant