From 818cdc5b196a7fe32c922af5e2e0b001e186dc3a Mon Sep 17 00:00:00 2001 From: Konstantin Gogov Date: Fri, 18 Sep 2026 11:07:36 +0300 Subject: [PATCH] ci: use GitHub App token for semantic-release push to master Replace GITHUB_TOKEN with a dedicated GitHub App installation token so that semantic-release can push the version bump commit directly to the protected master branch. - Add generate-token step using actions/create-github-app-token@v3 - Use client-id / RELEASE_APP_CLIENT_ID (v3 preferred input) - Pass the app token to semantic-release via GITHUB_TOKEN env var The GitHub App (UI5 Inspector Release Bot) must be installed on this repository and added as a bypass actor on the master branch protection rule for the push to succeed. --- .github/workflows/release.yml | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 2cfb3006..4687a0f2 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -22,11 +22,17 @@ jobs: run: npm ci - name: Run tests run: grunt test + - name: Generate release token + id: app-token + uses: actions/create-github-app-token@v3 + with: + client-id: ${{ secrets.RELEASE_APP_CLIENT_ID }} + private-key: ${{ secrets.RELEASE_APP_PRIVATE_KEY }} # Release using semantic-release if there are new semantic commits. # The @semantic-release/git plugin commits the version bump # (package.json, package-lock.json, app/manifest.json, CHANGELOG.md) # directly back to master. - name: Release env: - GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} + GITHUB_TOKEN: ${{ steps.app-token.outputs.token }} run: npx semantic-release