Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/workflows/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -113,7 +113,7 @@ and GitHub restricts it by default from 2026-11-02.

| Secret | Holds |
| --- | --- |
| `DEPENDABOT_REPAIR_APP_ID` | the numeric App identifier |
| `DEPENDABOT_REPAIR_APP_ID` | the App's Client ID, passed to the token action's `client-id` input (the numeric App ID is not stored) |
| `DEPENDABOT_REPAIR_APP_PRIVATE_KEY` | the App's PEM private key |

A repository admin provisions both by hand. The procedure — creating the App, granting it contents
Expand Down
6 changes: 3 additions & 3 deletions .github/workflows/dependabot-repair.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,8 +10,8 @@ name: dependabot-repair
# name appears nowhere in this file: it is a security regression for a convenience gain, and GitHub
# restricts it by default from 2026-11-02.
#
# Credential: a GitHub App installation token minted from DEPENDABOT_REPAIR_APP_ID and
# DEPENDABOT_REPAIR_APP_PRIVATE_KEY. When those secrets are absent the token step fails, the job
# Credential: a GitHub App installation token minted from the App's Client ID, stored in
# DEPENDABOT_REPAIR_APP_ID, and the private key in DEPENDABOT_REPAIR_APP_PRIVATE_KEY. When those secrets are absent the token step fails, the job
# stops before it can push, and the pull request keeps the behaviour it has today. See
# .github/workflows/README.md for the degraded mode and the installation runbook.

Expand Down Expand Up @@ -48,7 +48,7 @@ jobs:
id: app-token
uses: actions/create-github-app-token@v3
with:
app-id: ${{ secrets.DEPENDABOT_REPAIR_APP_ID }}
client-id: ${{ secrets.DEPENDABOT_REPAIR_APP_ID }}
private-key: ${{ secrets.DEPENDABOT_REPAIR_APP_PRIVATE_KEY }}

- name: Checkout the Dependabot branch
Expand Down
2 changes: 0 additions & 2 deletions QuickFiler.Test/QuickFiler.Test.csproj
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,6 @@
<Import Project="..\packages\Microsoft.Testing.Extensions.Telemetry.2.4.1\build\netstandard2.0\Microsoft.Testing.Extensions.Telemetry.props" Condition="Exists('..\packages\Microsoft.Testing.Extensions.Telemetry.2.4.1\build\netstandard2.0\Microsoft.Testing.Extensions.Telemetry.props')" />
<Import Project="..\packages\Microsoft.Testing.Platform.2.4.1\build\netstandard2.0\Microsoft.Testing.Platform.props" Condition="Exists('..\packages\Microsoft.Testing.Platform.2.4.1\build\netstandard2.0\Microsoft.Testing.Platform.props')" />
<Import Project="..\packages\Meziantou.Analyzer.3.0.290\build\Meziantou.Analyzer.props" Condition="Exists('..\packages\Meziantou.Analyzer.3.0.290\build\Meziantou.Analyzer.props')" />
<Import Project="..\packages\altcover.8.6.45\build\netstandard2.0\AltCover.props" Condition="Exists('..\packages\altcover.8.6.45\build\netstandard2.0\AltCover.props')" />
<Import Project="$(MSBuildExtensionsPath)\$(MSBuildToolsVersion)\Microsoft.Common.props" Condition="Exists('$(MSBuildExtensionsPath)\$(MSBuildToolsVersion)\Microsoft.Common.props')" />
<PropertyGroup>
<Configuration Condition=" '$(Configuration)' == '' ">Debug</Configuration>
Expand Down Expand Up @@ -534,7 +533,6 @@
</ItemGroup>
<Import Project="$(VSToolsPath)\TeamTest\Microsoft.TestTools.targets" Condition="Exists('$(VSToolsPath)\TeamTest\Microsoft.TestTools.targets')" />
<Import Project="$(MSBuildToolsPath)\Microsoft.CSharp.targets" />
<Import Project="..\packages\altcover.8.6.45\build\netstandard2.0\AltCover.targets" Condition="Exists('..\packages\altcover.8.6.45\build\netstandard2.0\AltCover.targets')" />
<Target Name="EnsureNuGetPackageBuildImports" BeforeTargets="PrepareForBuild">
<PropertyGroup>
<ErrorText>This project references NuGet package(s) that are missing on this computer. Use NuGet Package Restore to download them. For more information, see http://go.microsoft.com/fwlink/?LinkID=322105. The missing file is {0}.</ErrorText>
Expand Down
4 changes: 2 additions & 2 deletions SVGControl/app.config
Original file line number Diff line number Diff line change
Expand Up @@ -12,11 +12,11 @@
</dependentAssembly>
<dependentAssembly>
<assemblyIdentity name="Fizzler" publicKeyToken="4ebff4844e382110" culture="neutral" />
<bindingRedirect oldVersion="0.0.0.0-1.3.0.0" newVersion="1.3.0.0" />
<bindingRedirect oldVersion="0.0.0.0-1.3.1.0" newVersion="1.3.1.0" />
</dependentAssembly>
<dependentAssembly>
<assemblyIdentity name="System.Runtime.CompilerServices.Unsafe" publicKeyToken="b03f5f7f11d50a3a" culture="neutral" />
<bindingRedirect oldVersion="0.0.0.0-6.0.2.0" newVersion="6.0.2.0" />
<bindingRedirect oldVersion="0.0.0.0-6.0.3.0" newVersion="6.0.3.0" />
</dependentAssembly>
</assemblyBinding>
</runtime>
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -96,13 +96,13 @@ permissions listed in step 6 below and skip to step 10.
8. Under **Where can this GitHub App be installed?**, select **Only on this account**.
9. Click **Create GitHub App**.

### Part B — Record the App ID and generate a private key
### Part B — Record the Client ID and generate a private key

10. On the App's settings page that appears after creation, locate the **App ID** in the "About"
section near the top of the page and record it. The adjacent **Client ID** is also shown; record
it as well, because the `actions/create-github-app-token` action now documents `client-id` as
the recommended input and continues to accept the legacy `app-id` input. Neither value is a
secret in the cryptographic sense, but this runbook stores the App ID as a repository secret to
10. On the App's settings page that appears after creation, locate the **Client ID** in the "About"
section near the top of the page and record it. The numeric **App ID** shown beside it is not
needed: the repair workflow passes the Client ID to the `actions/create-github-app-token` action
as its `client-id` input, which the action documents as the recommended input. The Client ID is
not a secret in the cryptographic sense, but this runbook stores it as a repository secret to
keep the workflow configuration uniform.
11. On the same page, scroll to the **Private keys** section and click **Generate a private key**.
A `.pem` file downloads automatically. GitHub issues the key in PKCS#1 `RSAPrivateKey` PEM
Expand All @@ -126,9 +126,9 @@ permissions listed in step 6 below and skip to step 10.
19. Click **Settings** on the repository navigation bar.
20. In the sidebar's "Security" section, select **Secrets and variables**, then **Actions**.
21. Select the **Secrets** tab, then click **New repository secret**.
22. Create the App ID secret:
22. Create the Client ID secret:
- **Name** — `DEPENDABOT_REPAIR_APP_ID`
- **Secret** — the App ID value recorded in step 10
- **Secret** — the Client ID value recorded in step 10
- Click **Add secret**.
23. Click **New repository secret** again and create the private key secret:
- **Name** — `DEPENDABOT_REPAIR_APP_PRIVATE_KEY`
Expand All @@ -151,7 +151,7 @@ permissions listed in step 6 below and skip to step 10.
id: app-token
uses: actions/create-github-app-token@v3
with:
app-id: ${{ secrets.DEPENDABOT_REPAIR_APP_ID }}
client-id: ${{ secrets.DEPENDABOT_REPAIR_APP_ID }}
private-key: ${{ secrets.DEPENDABOT_REPAIR_APP_PRIVATE_KEY }}

- name: Check out the Dependabot branch
Expand Down
Loading
Loading