Skip to content

fix: remove COPILOT_PAT, use the native copilot-requests: write permission instead - #29

Merged
TaffarelJr merged 1 commit into
mainfrom
fix/remove-copilot-pat
Sep 13, 2026
Merged

TaffarelJr merged 1 commit into
mainfrom
fix/remove-copilot-pat

Conversation

@TaffarelJr

Copy link
Copy Markdown
Owner

Follow-up from the draft-release review

The COPILOT_PAT-based auth for the release-notes summary hit
Error: Authentication failed on a real run - the PAT lacked the right
scope. Rather than fix the PAT, switched to what GitHub now recommends:
Copilot CLI in GitHub Actions no longer needs a personal access
token
-
a workflow just needs the copilot-requests: write permission and
authenticates with its own built-in GITHUB_TOKEN.

  • draft-release.yml: declares copilot-requests: write, stops passing
    copilot-pat at all.
  • New-Repo.ps1: removes the CopilotToken prompt and the COPILOT_PAT
    secret-set - one fewer token to create, store, or rotate per repo.
  • Docs/skill updated to match: docs/ReleaseProcess.md's "Getting the
    token" section is gone, replaced with the permission-based story;
    .claude/skills/release/SKILL.md's troubleshooting note no longer
    mentions the PAT.

Open caveat, carried into the docs rather than guessed at: the billing
description for this native flow talks about organization-owned repos (a
Copilot policy toggle). .actions is a personal-account repo - whether the
same free path applies identically there hasn't been confirmed by a real
run yet. Once this syncs down and .actions' own PAT/secret is removed
too, a real draft-release run will confirm or refute it.

Full suite: 599 passed, 0 failed.

Next, in .actions (its own PR, after this merges and syncs down):
draft-release/action.yml loses the copilot-pat input and
COPILOT_GITHUB_TOKEN env var; the COPILOT_PAT repo secret gets deleted;
this repo's own local COPILOT_PAT user-scope environment variable gets
cleared too.

…ssion instead

Copilot CLI in GitHub Actions no longer needs a personal access token:
a workflow just needs the copilot-requests: write permission and
authenticates with its own built-in GITHUB_TOKEN. draft-release.yml
now declares that permission and no longer passes copilot-pat at all.

Removes the whole PAT lifecycle this repo used to manage: the
CopilotToken prompt and COPILOT_PAT secret-set in New-Repo.ps1, and
every doc/skill reference to creating, storing, or reading it.

Caveat carried into the docs: the billing story for this native flow
is described in terms of organization-owned repos (a Copilot policy
toggle). Whether the same free path applies identically to a
personal-account repo is not yet confirmed by a real run.
@TaffarelJr
TaffarelJr merged commit 5d504b6 into main Sep 13, 2026
4 checks passed
@TaffarelJr
TaffarelJr deleted the fix/remove-copilot-pat branch September 13, 2026 12:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant