Skip to content

ci: Fix deprecated client-id param in update job actions - #438

Merged
acoulton merged 1 commit into
Behat:masterfrom
acoulton:ci-update-job-action-deprecation
Sep 16, 2026
Merged

acoulton merged 1 commit into
Behat:masterfrom
acoulton:ci-update-job-action-deprecation

Conversation

@acoulton

Copy link
Copy Markdown
Contributor

Our cucumber-update job uses the create-github-app-token action to create a GitHub token to commit with so that it triggers CI.

create-github-app-token deprecated the client-id input in favour of app-id in their 3.1.0 release back in April.

However we did not detect this until reviewdog/actionlint v1.75.0 was released this morning, because they have just switched to a newer fork of actionlint that detects a wider range of issues including deprecated inputs.

Hence CI was fine yesterday, but broke when I merged this morning.

I have switched over to the new client-id input and provisioned the client ID in the repository settings.

As per https://github.blog/changelog/2024-05-01-github-apps-can-now-use-the-client-id-to-fetch-installation-tokens/ the client ID is not a secret & is expected to be visible to end users.

Our cucumber-update job uses the create-github-app-token
action to create a GitHub token to commit with so that it triggers CI.

create-github-app-token deprecated the `client-id` input in favour of
`app-id` in their [3.1.0 release back in April](https://github
.com/actions/create-github-app-token/releases/tag/v3.1.0)

However we did not detect this until
[reviewdog/actionlint v1.75.0](https://github.com/reviewdog/action-actionlint/releases/tag/v1.75.0)
was released this morning, because they have just switched to a newer
fork of actionlint that detects a wider range of issues including
deprecated inputs.

Hence CI was fine yesterday, but broke when I merged this morning.

I have switched over to the new `client-id` input and provisioned the
client ID in the repository settings.

As per
https://github.blog/changelog/2024-05-01-github-apps-can-now-use-the-client-id-to-fetch-installation-tokens/
the client ID is not a secret & is expected to be visible to end users.
@codecov

codecov Bot commented Sep 16, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 95.76%. Comparing base (37ee22e) to head (9e5030a).
✅ All tests successful. No failed tests found.

Additional details and impacted files
@@            Coverage Diff            @@
##             master     #438   +/-   ##
=========================================
  Coverage     95.76%   95.76%           
  Complexity      697      697           
=========================================
  Files            46       46           
  Lines          2080     2080           
=========================================
  Hits           1992     1992           
  Misses           88       88           
Flag Coverage Δ
php8.1 95.76% <ø> (ø)
php8.1--with=symfony/yaml:^5.4 95.76% <ø> (ø)
php8.1--with=symfony/yaml:^6.4 95.76% <ø> (ø)
php8.2 95.76% <ø> (ø)
php8.3 95.76% <ø> (ø)
php8.4 95.76% <ø> (ø)
php8.5 95.76% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

@acoulton
acoulton merged commit 0a87b6d into Behat:master Sep 16, 2026
13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants