Skip to content

Create the GitHub App for board writes and security-alert reads, and store its credentials as org secrets #2544

Description

@cliffhall

Problem

Three planned automations write to the org project board or read security alerts, and all are blocked on the same missing credential: GHSA draft cards (#2462), nightly triage (#2463), and the security sweep (#2542). dependabot-alerts.yml already reads secrets.PROJECT_TOKEN, but the secret does not exist, so the daily sweep files issues it cannot board.

The built-in GITHUB_TOKEN cannot hold organization projects: write, so the board write needs a separate identity. The App's spec currently lives inside #2462's body; this issue gives the prerequisite its own card.

What to create

A GitHub App installed on the modelcontextprotocol org, on the inspector repository only. It is only an identity with permissions: no code and no server. Workflows mint a short-lived installation token from it on each run with actions/create-github-app-token.

Scope Permission Needed by
Organization Projects: read & write every board write (#2462, #2463, #2542, the Dependabot sweep)
Repository Issues: read & write filing, labeling and commenting on issues
Repository Repository security advisories: read GHSA draft cards (#2462)
Repository Dependabot alerts: read the Dependabot sweep (#2542)
Repository Code scanning alerts: read the code-scanning sweep (#2542)
Repository Administration: read (optional) makes the sweep's automated-security-fixes check a real assertion instead of UNVERIFIED

Grant nothing beyond this list. In particular: no Contents write, no Workflows, no Secrets.

Storage

  • The App id and private key go in org Actions secrets limited to the inspector repo (for example INSPECTOR_BOT_APP_ID and INSPECTOR_BOT_PRIVATE_KEY).
  • Record the chosen secret names in AGENTS.md, next to the sweep sections that consume them.

Notes

  • This is an org-admin act and stays human-gated. An agent cannot create or install the App.
  • The fallback is a fine-grained PAT with the same permissions, stored as PROJECT_TOKEN. It is quicker to set up, but it is tied to one person and must be rotated by hand. The App is preferred.

Acceptance

  • App created and installed on inspector only, with exactly the permissions above
  • App id and private key stored as org Actions secrets limited to inspector
  • Secret names recorded in AGENTS.md
  • A throwaway workflow_dispatch run mints a token and reads the board, proving the install before the sweeps depend on it

Part of tracker #2543. Every board-writing sub-issue there is blocked on this one.

Activity

  1. added this to the v2.10.0 milestone on Sep 30, 2026
  2. added
    v2Issues and PRs for v2
    choreMaintenance: deps, build tooling, CI, cleanup — no user-facing behavior change
    on Sep 30, 2026
  3. cliffhall commented on Sep 30, 2026

    @cliffhall
    MemberAuthor

    Triage: Priority High (total 10)

    Board: #28, Status Todo. Part of tracker #2543.

  4. modified the milestones: v2.10.0, v2.11.0 on Oct 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    choreMaintenance: deps, build tooling, CI, cleanup — no user-facing behavior changev2Issues and PRs for v2

    Type

    No type

    Projects

    No projects

      Milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions