Skip to content

ci(changelog): use WAILS_REPO_TOKEN (CHANGELOG_PUSH_TOKEN is expired) - #5667

Merged
leaanthony merged 2 commits into
masterfrom
chore/fix-changelog-push-token
Jun 24, 2026
Merged

leaanthony merged 2 commits into
masterfrom
chore/fix-changelog-push-token

Conversation

@taliesin-ai

@taliesin-ai taliesin-ai commented Jun 24, 2026 •

Copy link
Copy Markdown
Collaborator

Switches the auto-changelog checkout/push from the expired CHANGELOG_PUSH_TOKEN (last set 2026-04-15) to WAILS_REPO_TOKEN (the token nightly-release-v3 uses to push to master successfully every night). This was the cause of every auto-changelog run failing at Checkout master. The expired CHANGELOG_PUSH_TOKEN secret can be deleted.

(The OpenRouter provider revert is handled separately.)

…_TOKEN expired)

Every auto-changelog run has been failing at 'Checkout master' with
'could not read Username for https://github.com' — the CHANGELOG_PUSH_TOKEN
secret (last set 2026-04-15) is expired, and it's used for both the checkout
and the push-to-master. This predates and is unrelated to the GitHub Models
switch; the LLM step never even ran.

Switch both to WAILS_REPO_TOKEN, the token nightly-release-v3 already uses to
push to master successfully every night (secret refreshed 2026-06-13). The
expired CHANGELOG_PUSH_TOKEN secret can then be deleted.
@coderabbitai

coderabbitai Bot commented Jun 24, 2026 •

Copy link
Copy Markdown
Contributor

Review Change Stack

Walkthrough

The auto-changelog-v3.yml GitHub Actions workflow is updated to replace the CHANGELOG_PUSH_TOKEN secret with WAILS_REPO_TOKEN in two places: the checkout step token selection and the git push authentication URL. Both still fall back to GITHUB_TOKEN.

Changes

Auto Changelog Workflow Token Update

Layer / File(s) Summary
Checkout and push token secret rename
.github/workflows/auto-changelog-v3.yml
The secret name used for authentication in both the checkout step (line 33) and the git push URL (line 87) is changed from CHANGELOG_PUSH_TOKEN to WAILS_REPO_TOKEN, with GITHUB_TOKEN as fallback in both cases.

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~2 minutes

Possibly related PRs

  • wailsapp/wails#5282: Also modifies auto-changelog-v3.yml authentication/secret handling, adjusting how secrets are made available to the workflow's checkout and push steps.

Suggested reviewers

  • leaanthony

Poem

🐇 A token by another name,
still opens the repo door the same.
CHANGELOG_PUSH_TOKEN steps aside,
WAILS_REPO_TOKEN takes the ride.
Two lines changed, the workflow's fine —
the rabbit approves every line! ✨

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Description check ⚠️ Warning The description covers the problem, fix, and context, but it misses the required issue link, testing, type of change, and checklist details. Add a Fixes #<issue> reference, fill in the type/test sections and checklist, and include any needed dependency notes.
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title is concise and accurately summarizes the workflow token switch, matching the main change.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch chore/fix-changelog-push-token

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
.github/workflows/auto-changelog-v3.yml (1)

28-33: 🔒 Security & Privacy | 🟠 Major | ⚡ Quick win

Disable checkout credential persistence.

actions/checkout is still persisting credentials in git config. Since this job already uses an explicit tokenized push URL, keep least-privilege by disabling persisted credentials.

Suggested patch
     - name: Checkout master
       uses: actions/checkout@v4
       with:
         ref: master
         fetch-depth: 0
+        persist-credentials: false
         token: ${{ secrets.WAILS_REPO_TOKEN || secrets.GITHUB_TOKEN }}
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/auto-changelog-v3.yml around lines 28 - 33, The Checkout
step in the auto-changelog workflow is still persisting Git credentials in the
local git config; update the actions/checkout usage for the “Checkout master”
step to disable credential persistence while keeping the existing token-based
ref checkout. Make the change in the checkout configuration itself by setting
the appropriate persisted-credentials option on that step so the job continues
to use the explicit tokenized push URL without leaving credentials behind.

Source: Linters/SAST tools

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Outside diff comments:
In @.github/workflows/auto-changelog-v3.yml:
- Around line 28-33: The Checkout step in the auto-changelog workflow is still
persisting Git credentials in the local git config; update the actions/checkout
usage for the “Checkout master” step to disable credential persistence while
keeping the existing token-based ref checkout. Make the change in the checkout
configuration itself by setting the appropriate persisted-credentials option on
that step so the job continues to use the explicit tokenized push URL without
leaving credentials behind.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: 2c5ad4ae-e952-44d3-a678-211d73d0fcee

📥 Commits

Reviewing files that changed from the base of the PR and between db24add and 6e89f93.

📒 Files selected for processing (1)
  • .github/workflows/auto-changelog-v3.yml

@leaanthony
leaanthony enabled auto-merge (squash) June 24, 2026 11:31
@leaanthony
leaanthony disabled auto-merge June 24, 2026 11:32
@leaanthony
leaanthony enabled auto-merge (squash) June 24, 2026 11:32
@leaanthony
leaanthony merged commit a51c1d0 into master Jun 24, 2026
35 of 36 checks passed
@leaanthony
leaanthony deleted the chore/fix-changelog-push-token branch June 24, 2026 11:33
@taliesin-ai taliesin-ai changed the title ci(changelog): use WAILS_REPO_TOKEN (CHANGELOG_PUSH_TOKEN is expired) ci(changelog): restore automation — WAILS_REPO_TOKEN + revert to OpenRouter Jun 24, 2026
@taliesin-ai taliesin-ai changed the title ci(changelog): restore automation — WAILS_REPO_TOKEN + revert to OpenRouter ci(changelog): use WAILS_REPO_TOKEN (CHANGELOG_PUSH_TOKEN is expired) Jun 24, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants