Repository navigation
refactor(apply-repo-settings): action is now a pure merge — no templating - #43
Merged
Merged
Conversation
nsheaps
approved these changes
May 29, 2026
… runtime When a pre-generated installation token is provided, app-id is no longer required. The action now derives APP_ID from the token via GET /app when the input is omitted, so callers using checkout-as-app don't need to pass the secret twice. Auth fallback (token == '') still requires app-id + private-key. https://claude.ai/code/session_01XUJx6sKWxyKyoWdxNEsET1
…-time resolution actor_id: -1 placeholders are now resolved by .github/sync-repo-settings before distribution, so action.sh no longer needs to substitute them. APP_ID kept as an optional fallback for standalone use with unresolved files. https://claude.ai/code/session_01XUJx6sKWxyKyoWdxNEsET1
…ure merge The action no longer takes app-id or private-key — it requires only a pre-generated token (with administration:write). It applies the settings file verbatim, with no placeholder substitution. Templating moved upstream to nsheaps/.github, where repo-settings.template.yaml is rendered (envsubst) into repo-settings.yaml at the source. https://claude.ai/code/session_01XUJx6sKWxyKyoWdxNEsET1
Some runners pre-install kislyuk's Python yq (a jq wrapper) at /usr/bin/yq. The previous check skipped install when 'yq' was on PATH — but Python yq doesn't support '-o=json' and the action failed with exit 3 (jq compile error 'Unknown option -o=json'). Now: probe '--version' for the mikefarah marker. If absent, install mikefarah/yq to /usr/local/bin/yq and prepend it via GITHUB_PATH so subsequent steps shadow any wrong yq.
nsheaps
force-pushed
the
claude/practical-shannon-a2n2d
branch
from
May 29, 2026 15:52
b2fc5fc to
51822dd
Compare
Triggered by: 5fc6327 Workflow run: https://github.com/nsheaps/github-actions/actions/runs/26647393901
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Simplify
apply-repo-settingsto a pure merge — drop allapp-id/private-key/runtime templating from the action. The action takes atoken, readssettings.yml, and applies it. Callers handle auth.Also fixes a yq detection bug that caused the action to silently fail on runners with kislyuk's Python
yqpre-installed.Changes
Pure merge (action.yml + action.sh)
app-id,private-key,token-as-optional.tokenis the only auth input and is required.actor_id: -1placeholder substitution logic from action.sh. Templating belongs upstream (see nsheaps/.github#134 — render workflow + envsubst before sync).yq detection fix (action.yml)
command -v yqmatches anyyqon PATH — including kislyuk/yq(a Python wrapper aroundjqthat does NOT support-o=json). When that runs, the action exits with code 3 (jqcompile error "Unknown option -o=json"), with no clear indication that the wrong tool is in use.yq --versionfor themikefarahmarker. If absent, install mikefarah's yq to/usr/local/bin/yqand prepend that path via$GITHUB_PATHso subsequent steps shadow the wrong tool. Added a final sanity check that the resolved binary IS mikefarah.Tested
nsheaps/.githubsettings.yml: dry-run succeeds (1 ruleset updated, 4 created, exit only fails on$GITHUB_OUTPUTunset which is a local-only thing).Related
bypass_actorscruft (merged)🤖