diff --git a/VERSION b/VERSION index 1a5ac0d..04e84f8 100644 --- a/VERSION +++ b/VERSION @@ -1 +1 @@ -0.6.9 +0.6.10 diff --git a/actions/release-post-merge/action.yml b/actions/release-post-merge/action.yml index 3759060..b07ea36 100644 --- a/actions/release-post-merge/action.yml +++ b/actions/release-post-merge/action.yml @@ -154,21 +154,11 @@ runs: prepared_id="$(php -r '$p=json_decode(file_get_contents($argv[1]),true,512,JSON_THROW_ON_ERROR); echo $p["id"];' "${RELEASE_STATE_DIR}/prepared-release.json")" echo "prepared-release-id=${prepared_id}" >> "${GITHUB_OUTPUT}" - - id: milestone-token - name: Create milestone token - uses: actions/create-github-app-token@67018539274d69449ef7c02e8e71183d1719ab42 # v2.1.4 - with: - app-id: ${{ inputs.app-id }} - private-key: ${{ inputs.app-private-key }} - owner: ${{ steps.repository.outputs.owner }} - repositories: ${{ steps.repository.outputs.name }} - permission-issues: write - - id: milestone name: Apply milestone transition shell: bash env: - GITHUB_TOKEN: ${{ steps.milestone-token.outputs.token }} + GITHUB_TOKEN: ${{ inputs.github-token }} RELEASE_TOOL_PATH: ${{ steps.setup.outputs.path }} RELEASE_CONFIG_PATH: ${{ inputs.config-path }} RELEASE_STATE_DIR: ${{ runner.temp }}/release-post-merge-state diff --git a/tests/test_release_post_merge_action.py b/tests/test_release_post_merge_action.py index a80315f..f42d356 100644 --- a/tests/test_release_post_merge_action.py +++ b/tests/test_release_post_merge_action.py @@ -29,13 +29,14 @@ def test_authorization_happens_before_mutation(self) -> None: self.assertLess(milestone, draft) self.assertIn("merge_min_permission", content) - def test_each_mutating_stage_uses_scoped_app_token(self) -> None: + def test_mutating_stages_use_scoped_tokens(self) -> None: content = ACTION.read_text(encoding="utf-8") - self.assertEqual(3, content.count("actions/create-github-app-token@67018539274d69449ef7c02e8e71183d1719ab42")) + self.assertEqual(2, content.count("actions/create-github-app-token@67018539274d69449ef7c02e8e71183d1719ab42")) self.assertIn("permission-contents: write", content) self.assertIn("permission-pull-requests: write", content) - self.assertIn("permission-issues: write", content) + self.assertNotIn("permission-issues: write", content) self.assertIn("permission-pull-requests: read", content) + self.assertIn("GITHUB_TOKEN: ${{ inputs.github-token }}", content) def test_contract_chain_is_persisted_for_publication(self) -> None: content = ACTION.read_text(encoding="utf-8")