Skip to content

refactor(apply-repo-settings): action is now a pure merge — no templating - #43

Merged
nsheaps merged 5 commits into
mainfrom
claude/practical-shannon-a2n2d
May 29, 2026
Merged

nsheaps merged 5 commits into
mainfrom
claude/practical-shannon-a2n2d

Conversation

@jack-nsheaps

@jack-nsheaps jack-nsheaps Bot commented May 29, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Simplify apply-repo-settings to a pure merge — drop all app-id/private-key/runtime templating from the action. The action takes a token, reads settings.yml, and applies it. Callers handle auth.

Also fixes a yq detection bug that caused the action to silently fail on runners with kislyuk's Python yq pre-installed.

Changes

Pure merge (action.yml + action.sh)

  • Drop app-id, private-key, token-as-optional. token is the only auth input and is required.
  • Drop the actor_id: -1 placeholder substitution logic from action.sh. Templating belongs upstream (see nsheaps/.github#134 — render workflow + envsubst before sync).
  • Result: the action just reads the YAML and applies it via the GitHub API. ~14 lines removed from action.sh.

yq detection fix (action.yml)

  • Previous check command -v yq matches any yq on PATH — including kislyuk/yq (a Python wrapper around jq that does NOT support -o=json). When that runs, the action exits with code 3 (jq compile error "Unknown option -o=json"), with no clear indication that the wrong tool is in use.
  • New check probes yq --version for the mikefarah marker. If absent, install mikefarah's yq to /usr/local/bin/yq and prepend that path via $GITHUB_PATH so subsequent steps shadow the wrong tool. Added a final sanity check that the resolved binary IS mikefarah.

Tested

  • Locally with mikefarah/yq + the cleaned nsheaps/.github settings.yml: dry-run succeeds (1 ruleset updated, 4 created, exit only fails on $GITHUB_OUTPUT unset which is a local-only thing).

Related

🤖

@jack-nsheaps jack-nsheaps Bot changed the title fix(apply-repo-settings): make app-id optional; actor_id resolved at sync time refactor(apply-repo-settings): action is now a pure merge — no templating May 29, 2026
nsheaps added 4 commits May 29, 2026 15:52
… runtime

When a pre-generated installation token is provided, app-id is no
longer required. The action now derives APP_ID from the token via
GET /app when the input is omitted, so callers using checkout-as-app
don't need to pass the secret twice.

Auth fallback (token == '') still requires app-id + private-key.

https://claude.ai/code/session_01XUJx6sKWxyKyoWdxNEsET1
…-time resolution

actor_id: -1 placeholders are now resolved by .github/sync-repo-settings
before distribution, so action.sh no longer needs to substitute them.
APP_ID kept as an optional fallback for standalone use with unresolved files.

https://claude.ai/code/session_01XUJx6sKWxyKyoWdxNEsET1
…ure merge

The action no longer takes app-id or private-key — it requires only a
pre-generated token (with administration:write). It applies the settings
file verbatim, with no placeholder substitution.

Templating moved upstream to nsheaps/.github, where repo-settings.template.yaml
is rendered (envsubst) into repo-settings.yaml at the source.

https://claude.ai/code/session_01XUJx6sKWxyKyoWdxNEsET1
Some runners pre-install kislyuk's Python yq (a jq wrapper) at /usr/bin/yq.
The previous check skipped install when 'yq' was on PATH — but Python yq
doesn't support '-o=json' and the action failed with exit 3 (jq compile
error 'Unknown option -o=json').

Now: probe '--version' for the mikefarah marker. If absent, install
mikefarah/yq to /usr/local/bin/yq and prepend it via GITHUB_PATH so
subsequent steps shadow any wrong yq.
@nsheaps
nsheaps force-pushed the claude/practical-shannon-a2n2d branch from b2fc5fc to 51822dd Compare May 29, 2026 15:52
@nsheaps
nsheaps marked this pull request as ready for review May 29, 2026 18:02
@nsheaps
nsheaps merged commit 4865821 into main May 29, 2026
2 checks passed
@nsheaps
nsheaps deleted the claude/practical-shannon-a2n2d branch May 29, 2026 18:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant