Skip to content

Commit 8e83c40

Browse files
committed
chore(wheelhouse): cascade template@dcd3bac340
Auto-applied by socket-wheelhouse commit-cascade into socket-lib. 9 file(s) touched: - .config/fleet/oxlintrc.json - .github/actions/fleet/github-pr-branch-app-token/action.yml - .github/actions/fleet/github-pr-branch-app-token/mint-app-installation-token.mjs - .npmrc - AGENTS.md - pnpm-workspace.yaml - scripts/repo/bootstrap/fleet.mjs - .github/actions/fleet/github-pr-branch-app-token - scripts/repo/bootstrap
1 parent 747c08b commit 8e83c40

8 files changed

Lines changed: 271 additions & 270 deletions

File tree

‎.config/fleet/oxlintrc.json‎

Lines changed: 2 additions & 0 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

‎.github/actions/fleet/github-pr-branch-app-token/action.yml‎

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: PR branch app token
22
description: >-
3-
Mint a short-lived PR App installation token for owned non-default branch
4-
writes. Workflow files are outside this profile.
3+
Mint a short-lived PR App installation token for release branches and PRs.
4+
Workflow files are outside this profile.
55
66
inputs:
77
client-id:
@@ -36,7 +36,7 @@ runs:
3636
APP_PRIVATE_KEY: ${{ inputs.private-key }}
3737
CLIENT_ID: ${{ inputs.client-id }}
3838
OWNER: ${{ inputs.owner || github.repository_owner }}
39-
PERMISSIONS: '{"contents":"write"}'
39+
PERMISSIONS: '{"contents":"write","issues":"write","pull_requests":"write"}'
4040
REPOSITORIES: ${{ inputs.repositories }}
4141
GITHUB_ACTION_PATH: ${{ github.action_path }}
4242
run: node "${GITHUB_ACTION_PATH}/mint-app-installation-token.mjs"

‎.github/actions/fleet/github-pr-branch-app-token/mint-app-installation-token.mjs‎

Lines changed: 1 addition & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -311,10 +311,7 @@ async function main() {
311311
}
312312

313313
// PREFLIGHT: the installation's own grant must already cover every requested
314-
// scope. Runs before the mint and therefore before any publish/promote — the
315-
// widened `pull_requests: write` request is only exercised by the promote PR
316-
// that follows a successful publish, so without this the shortfall surfaces
317-
// as a 403 in the irreversible window.
314+
// scope. Runs before the mint and before any branch or pull-request write.
318315
if (permissions !== undefined) {
319316
const missing = findMissingAppPermissions({
320317
granted: installation.permissions,

‎.npmrc‎

Lines changed: 0 additions & 9 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

‎AGENTS.md‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -27,7 +27,7 @@
2727
- The `squash-history` opt-in tracks the release boundary: the first release FREEZES history through that commit, and only the unreleased tail squashes. [`squash-until-release`](docs/fleet/agents.md/squash-until-release.md)
2828
- `fleet-main-protection` blocks force-push, `fleet-tag-protection` blocks `v*` tag deletes. [`history-rewrites`](docs/fleet/agents.md/history-rewrites.md)
2929
- npm stages burn versions: minor default, odai patch/minor, major needs `X.Y.Z-prerelease`. [`version-bumps`](docs/fleet/agents.md/version-bumps.md)
30-
- NEVER open a pull request to land a version bump: the bump commit goes DIRECTLY on the default branch via the release App. (`.claude/hooks/fleet/no-version-bump-pr-guard/`) [`version-bumps`](docs/fleet/agents.md/version-bumps.md)
30+
- Never hand-create a version-bump PR. The npm publish workflow uses the PR App to sign the bump, open its reviewed PR, and resume staging after merge; the Release App handles Actions and release operations. (`.claude/hooks/fleet/no-version-bump-pr-guard/`) [`version-bumps`](docs/fleet/agents.md/version-bumps.md)
3131
- Dot-naming `@owner/<name>[.<lang>].<target>[-<platform>]`: the `.target` token carries the domain. [`binary-vs-napi-naming`](docs/fleet/agents.md/binary-vs-napi-naming.md)
3232
- A private package is unscoped `local-<directory>` at version `0.0.0`. [`private-package-identity`](docs/fleet/agents.md/private-package-identity.md)
3333
- Every `release.publishedPackages` entry is non-private and the set carries ONE version. (`scripts/fleet/check/published-packages-are-release-ready.mts`) [`private-package-identity`](docs/fleet/agents.md/private-package-identity.md)
@@ -158,7 +158,7 @@
158158
- Validate what SHIPS, not the source tree: the packed tarball's bytes, plus a leak scan of both. [`artifact-hygiene`](docs/fleet/agents.md/artifact-hygiene.md)
159159
- A `github-action` member ships committed `dist/` at a tag. (`scripts/fleet/check/github-action-aliases-are-not-frozen.mts`) [`github-action-release-contract`](docs/fleet/agents.md/github-action-release-contract.md)
160160
- GitHub CLI tokens: keychain only; `workflow` scope off by default; 8-hour age cap. [`gh-token-hygiene`](docs/fleet/agents.md/gh-token-hygiene.md)
161-
- Release App writes default-branch and release content. PR App writes repair branches, issues, and PRs. Both are organization-wide. [`token-hygiene`](docs/fleet/agents.md/token-hygiene.md)
161+
- Release App manages Actions runs and release content. PR App writes signed branches, issues, and PRs. Both are organization-wide. [`token-hygiene`](docs/fleet/agents.md/token-hygiene.md)
162162
- Commits on `main`/`master` must be signed. [`commit-signing`](docs/fleet/agents.md/commit-signing.md) [`git-config-write-guard`](docs/fleet/agents.md/git-config-write-guard.md)
163163
- Keep AI logic canonical; generate client aliases during setup, never commit them. [`release-vs-cascade`](docs/fleet/agents.md/release-vs-cascade.md)
164164
- Skills, commands, and agent instructions are thin wrappers. [`agents-and-skills`](docs/fleet/agents.md/agents-and-skills.md)

0 commit comments

Comments
 (0)