From 9e5030abcbad07dae06e8c1a71dbde12e780f14a Mon Sep 17 00:00:00 2001 From: acoulton Date: Wed, 16 Sep 2026 10:05:26 +0100 Subject: [PATCH] ci: Fix deprecated client-id param in update job actions Our cucumber-update job uses the create-github-app-token action to create a GitHub token to commit with so that it triggers CI. create-github-app-token deprecated the `client-id` input in favour of `app-id` in their [3.1.0 release back in April](https://github .com/actions/create-github-app-token/releases/tag/v3.1.0) However we did not detect this until [reviewdog/actionlint v1.75.0](https://github.com/reviewdog/action-actionlint/releases/tag/v1.75.0) was released this morning, because they have just switched to a newer fork of actionlint that detects a wider range of issues including deprecated inputs. Hence CI was fine yesterday, but broke when I merged this morning. I have switched over to the new `client-id` input and provisioned the client ID in the repository settings. As per https://github.blog/changelog/2024-05-01-github-apps-can-now-use-the-client-id-to-fetch-installation-tokens/ the client ID is not a secret & is expected to be visible to end users. --- .github/workflows/update.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/update.yml b/.github/workflows/update.yml index 9042361d..82058910 100644 --- a/.github/workflows/update.yml +++ b/.github/workflows/update.yml @@ -91,7 +91,7 @@ jobs: id: app-token if: steps.cucumber.outputs.cucumber_updated == 'yes' with: - app-id: ${{ vars.GHERKIN_UPDATER_APP_ID }} + client-id: ${{ vars.GHERKIN_UPDATER_APP_CLIENT_ID }} private-key: ${{ secrets.GHERKIN_UPDATER_APP_KEY }} - run: .github/commit-and-push-gherkin-update.sh