Skip to content

Replace legacy CI credentials - #35

Merged
alixander merged 1 commit into
masterfrom
agent/use-actions-token
Aug 3, 2026
Merged

Replace legacy CI credentials#35
alixander merged 1 commit into
masterfrom
agent/use-actions-token

Conversation

@alixander

Copy link
Copy Markdown
Contributor

Summary

  • replace the long-lived _GITHUB_TOKEN repository secret with the per-run github.token
  • grant only actions: read and contents: read to notification jobs
  • remove the unused Terrastruct-era credential writer and use D2 CI <ci@d2lang.com>
  • leave Slack webhook credentials unchanged

The old repository secret should be deleted only after this runs successfully on the protected default branch.

Validation

  • ./ci/ci.sh
  • YAML parse
  • shell syntax checks
  • deterministic lib.sh regeneration
  • actionlint (excluding existing old-action-version warnings)
  • git diff --check

@alixander
alixander marked this pull request as ready for review August 3, 2026 17:28
@alixander
alixander merged commit c3116b0 into master Aug 3, 2026
4 of 6 checks passed
@alixander
alixander deleted the agent/use-actions-token branch August 3, 2026 17:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant