Skip to content

Refactor sync workflow to use Github App - #115

Merged
pdabelf5 merged 2 commits into
mainfrom
chore/github-app-for-sync
Sep 11, 2026
Merged

pdabelf5 merged 2 commits into
mainfrom
chore/github-app-for-sync

Conversation

@pdabelf5

@pdabelf5 pdabelf5 commented Sep 4, 2026 •

Copy link
Copy Markdown
Collaborator

Proposed changes

This pull request updates the GitHub Actions workflows to improve security and modernize authentication for repository automation. The main changes involve removing the legacy Dependabot auto-merge workflow and refactoring the sync.yml workflow to use GitHub App tokens fetched from a vault, instead of personal access tokens.

Workflow deprecation:

  • Removed the .github/workflows/dependabot-auto-merge.yml workflow, discontinuing automatic merging of Dependabot PRs.

Authentication and security improvements:

  • Updated the sync.yml workflow to fetch GitHub App credentials from a vault using the get-from-vault action, and mint short-lived GitHub App tokens for each organization and repository, replacing the use of static personal access tokens.
  • Added explicit id-token: write and contents: read permissions for jobs, following GitHub Actions security best practices.

Repository sync and label management updates:

  • Refactored the label sync step to use the new GitHub App tokens and updated repository references from nginxinc to nginx where appropriate.
  • Split repository sync steps to use the appropriate minted token for each organization, ensuring least-privilege access.

Checklist

Before creating a PR, run through this checklist and mark each as complete:

@pdabelf5 pdabelf5 self-assigned this Sep 4, 2026
@pdabelf5
pdabelf5 force-pushed the chore/github-app-for-sync branch from 4d58cd9 to eaf6e34 Compare September 4, 2026 16:39
@pdabelf5
pdabelf5 merged commit 4ea3370 into main Sep 11, 2026
5 checks passed
@pdabelf5
pdabelf5 deleted the chore/github-app-for-sync branch September 11, 2026 09:24

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The App private key remains exposed to subsequent actions and subprocesses after token minting.

Once you've addressed the issues Copilot identified, you can request another Copilot review.

Pull request overview

Refactors repository automation to use short-lived GitHub App tokens and removes Dependabot auto-merge.

Changes:

  • Retrieves GitHub App credentials from Azure Key Vault.
  • Mints organization-scoped tokens for label and repository synchronization.
  • Removes the Dependabot auto-merge workflow.
File summaries
File Description
.github/workflows/sync.yml Migrates synchronization from PATs to GitHub App tokens.
.github/workflows/dependabot-auto-merge.yml Removes automated Dependabot merging.
Review details

Suppressed comments (1)

.github/workflows/sync.yml:101

  • After all three installation tokens are minted, the long-lived App private key remains inherited by every gh subprocess even though they only need GH_TOKEN. Clear APP_PRIVATE_KEY before starting the sync commands to minimize exposure of a credential that can mint tokens beyond these repository-scoped tokens.
      - name: Sync nginx-bot/certified-operators
  • Files reviewed: 2/2 changed files
  • Comments generated: 1
  • Review effort level: Balanced

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

nginx/nginx-asg-sync
nginx/telemetry-exporter
token: ${{ secrets.NGINX_PAT }}
token: ${{ steps.nginx-token.outputs.token }}
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants