Skip to content

chore(release): unify release automation as Oli bot - #252

Merged
f0rr0 merged 4 commits into
mainfrom
f0rr0/oli-release-bot
Oct 5, 2026
Merged

f0rr0 merged 4 commits into
mainfrom
f0rr0/oli-release-bot

Conversation

@f0rr0

@f0rr0 f0rr0 commented Oct 5, 2026 •

Copy link
Copy Markdown
Owner

Summary

Release preparation uses a separate RELEASE_PR_TOKEN, while asset uploads, attestations, and promotion use the built-in Actions identity. Route release PRs and all GitHub release mutations through the existing private GitHub App, with phase-scoped installation tokens. Keep built-in release mutation scopes read-only, retain actions: write in the dedicated CI dispatch job, and preserve workflow OIDC for registry authentication and provenance signing.

Use Oli [bot] for generated commit names and update the linked noreply address to the verified renamed account oli-release-bot[bot] (same user ID 326451763). Preserve frozen-candidate authorship. Renew Contents-only upload tokens five minutes before expiry, share refreshes across concurrent lanes, and revoke issued tokens after every lane drains. Draft inventories and bootstrap collision preflight use App credentials with Contents write so existing drafts remain visible. Update the controls audit and migration documentation.

Release Intent

  • Docs/CI/repository-only change: no release intended.
  • Package/API/runtime change.
  • Source/input/runtime asset change.

GitHub setup

The existing App is Oli Release Bot, with account oli-release-bot[bot] and unchanged numeric user ID. Its Client ID and verified private key are configured in all three protected environments: release-pr, release-bootstrap, and release-publish.

Live authentication confirmed Contents, Workflows, Issues, Pull requests, and Attestations read/write, plus Actions read-only, in both the App registration and accepted installation. Minting a token restricted to f0rr0/oliphaunt succeeded with those exact requested permissions. Read-only repository, release, PR, and Actions probes passed; the test token was revoked. The repository's default Actions token remains read-only.

After merge, run release PR preparation and confirm that an App-created PR starts normal PR CI. Then remove/revoke the obsolete RELEASE_PR_TOKEN and retire the old App key after confirming the migration works. Existing credentials remain active during migration.

Verification

  • Moon affected projects checked: release tools, workflow checks, docs, and repository policy; no product compilation selected.
  • moon run release-tools:js-format-check release-tools:js-lint
  • bash tools/release/release-check.sh --mutation-tests-only
  • bash tools/release/release-metadata-check.sh
  • bash tools/ci/check-workflows.sh (pinned actionlint, zizmor, and workflow behavior tests)
  • Focused App-token, mutation, and asset-upload tests: 49 passed.
  • Renamed bot login and unchanged numeric user ID verified against GitHub; supplied Client ID configured in all three release environments.
  • Release PR publication and source-bound SwiftPM identity/recovery tests passed after the bot email update.
  • Audit of remaining native-token consumers and pinned actions: repository reads retain read scopes; artifact uploads/overwrite use Actions runtime credentials; attestation API writes receive the App token. Regression assertions cover bootstrap/publication draft visibility, CI dispatch permissions, and OIDC permissions.
  • git diff --check
  • Live App authentication, installation permission grants, repository-scoped token creation, read-only API probes, and test-token revocation. Verified private key provisioned in all three protected environments.
  • End-to-end release PR preparation with the merged workflow and automatic PR CI. Public release publication was not exercised.

@vercel

vercel Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
oliphaunt-docs Ready Ready Preview Oct 5, 2026 2:38am UTC

@f0rr0
f0rr0 marked this pull request as ready for review October 5, 2026 02:52
@f0rr0
f0rr0 merged commit 4986f82 into main Oct 5, 2026
70 checks passed
@f0rr0
f0rr0 deleted the f0rr0/oli-release-bot branch October 5, 2026 03:00

This branch was successfully deployed

1 active deployment
Preview — 6f11cf59 Deployed Oct 5, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant