Repository navigation
ci(changelog): use WAILS_REPO_TOKEN (CHANGELOG_PUSH_TOKEN is expired) - #5667
Conversation
…_TOKEN expired) Every auto-changelog run has been failing at 'Checkout master' with 'could not read Username for https://github.com' — the CHANGELOG_PUSH_TOKEN secret (last set 2026-04-15) is expired, and it's used for both the checkout and the push-to-master. This predates and is unrelated to the GitHub Models switch; the LLM step never even ran. Switch both to WAILS_REPO_TOKEN, the token nightly-release-v3 already uses to push to master successfully every night (secret refreshed 2026-06-13). The expired CHANGELOG_PUSH_TOKEN secret can then be deleted.
WalkthroughThe ChangesAuto Changelog Workflow Token Update
Estimated code review effort🎯 1 (Trivial) | ⏱️ ~2 minutes Possibly related PRs
Suggested reviewers
Poem
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Caution
Some comments are outside the diff and can’t be posted inline due to platform limitations.
⚠️ Outside diff range comments (1)
.github/workflows/auto-changelog-v3.yml (1)
28-33: 🔒 Security & Privacy | 🟠 Major | ⚡ Quick winDisable checkout credential persistence.
actions/checkoutis still persisting credentials in git config. Since this job already uses an explicit tokenized push URL, keep least-privilege by disabling persisted credentials.Suggested patch
- name: Checkout master uses: actions/checkout@v4 with: ref: master fetch-depth: 0 + persist-credentials: false token: ${{ secrets.WAILS_REPO_TOKEN || secrets.GITHUB_TOKEN }}🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In @.github/workflows/auto-changelog-v3.yml around lines 28 - 33, The Checkout step in the auto-changelog workflow is still persisting Git credentials in the local git config; update the actions/checkout usage for the “Checkout master” step to disable credential persistence while keeping the existing token-based ref checkout. Make the change in the checkout configuration itself by setting the appropriate persisted-credentials option on that step so the job continues to use the explicit tokenized push URL without leaving credentials behind.Source: Linters/SAST tools
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Outside diff comments:
In @.github/workflows/auto-changelog-v3.yml:
- Around line 28-33: The Checkout step in the auto-changelog workflow is still
persisting Git credentials in the local git config; update the actions/checkout
usage for the “Checkout master” step to disable credential persistence while
keeping the existing token-based ref checkout. Make the change in the checkout
configuration itself by setting the appropriate persisted-credentials option on
that step so the job continues to use the explicit tokenized push URL without
leaving credentials behind.
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: CHILL
Plan: Pro
Run ID: 2c5ad4ae-e952-44d3-a678-211d73d0fcee
📒 Files selected for processing (1)
.github/workflows/auto-changelog-v3.yml
Switches the auto-changelog checkout/push from the expired
CHANGELOG_PUSH_TOKEN(last set 2026-04-15) toWAILS_REPO_TOKEN(the token nightly-release-v3 uses to push to master successfully every night). This was the cause of everyauto-changelogrun failing at Checkout master. The expiredCHANGELOG_PUSH_TOKENsecret can be deleted.(The OpenRouter provider revert is handled separately.)