Repository navigation
fix: remove COPILOT_PAT, use the native copilot-requests: write permission instead - #29
Merged
Merged
Conversation
…ssion instead Copilot CLI in GitHub Actions no longer needs a personal access token: a workflow just needs the copilot-requests: write permission and authenticates with its own built-in GITHUB_TOKEN. draft-release.yml now declares that permission and no longer passes copilot-pat at all. Removes the whole PAT lifecycle this repo used to manage: the CopilotToken prompt and COPILOT_PAT secret-set in New-Repo.ps1, and every doc/skill reference to creating, storing, or reading it. Caveat carried into the docs: the billing story for this native flow is described in terms of organization-owned repos (a Copilot policy toggle). Whether the same free path applies identically to a personal-account repo is not yet confirmed by a real run.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Follow-up from the draft-release review
The
COPILOT_PAT-based auth for the release-notes summary hitError: Authentication failedon a real run - the PAT lacked the rightscope. Rather than fix the PAT, switched to what GitHub now recommends:
Copilot CLI in GitHub Actions no longer needs a personal access
token -
a workflow just needs the
copilot-requests: writepermission andauthenticates with its own built-in
GITHUB_TOKEN.draft-release.yml: declarescopilot-requests: write, stops passingcopilot-patat all.New-Repo.ps1: removes theCopilotTokenprompt and theCOPILOT_PATsecret-set - one fewer token to create, store, or rotate per repo.
docs/ReleaseProcess.md's "Getting thetoken" section is gone, replaced with the permission-based story;
.claude/skills/release/SKILL.md's troubleshooting note no longermentions the PAT.
Open caveat, carried into the docs rather than guessed at: the billing
description for this native flow talks about organization-owned repos (a
Copilot policy toggle).
.actionsis a personal-account repo - whether thesame free path applies identically there hasn't been confirmed by a real
run yet. Once this syncs down and
.actions' own PAT/secret is removedtoo, a real
draft-releaserun will confirm or refute it.Full suite: 599 passed, 0 failed.
Next, in
.actions(its own PR, after this merges and syncs down):draft-release/action.ymlloses thecopilot-patinput andCOPILOT_GITHUB_TOKENenv var; theCOPILOT_PATrepo secret gets deleted;this repo's own local
COPILOT_PATuser-scope environment variable getscleared too.