Skip to content

fix: replace stale raw-token add-to-project workflow with reusable App-token pattern - #2

Merged
asachs01 merged 1 commit into
mainfrom
fix/add-to-project-reusable-workflow
Aug 28, 2026
Merged

asachs01 merged 1 commit into
mainfrom
fix/add-to-project-reusable-workflow

Conversation

@asachs01

@asachs01 asachs01 commented Aug 26, 2026 •

Copy link
Copy Markdown
Contributor

Root cause

add-to-project.yml used the legacy raw-token pattern:

- uses: actions/add-to-project@v1.0.2
  with:
    project-url: https://github.com/orgs/WYRE-AI/projects/1
    github-token: ${{ secrets.ADD_TO_PROJECT_TOKEN }}

secrets.ADD_TO_PROJECT_TOKEN does not exist in either wyre-technology or WYRE-AI — the fleet migrated off this raw-PAT pattern onto a reusable workflow that mints a short-lived GitHub App token instead, back around May 2026.

This is NOT an org-transfer casualty, and specifically not the same failure family as the GHCR-package-visibility or GHPKG_READ_TOKEN org-transfer issues seen on other repos. Those are carry-over gaps from moving a previously-working repo between orgs. This bug is different: it has been latent since this repo's creation.

Confirmed via git log:

  • Initial commit 7abb53e (2026-07-03) already scaffolded add-to-project.yml with the legacy secrets.ADD_TO_PROJECT_TOKEN pattern — two months after the fleet-wide migration to the reusable workflow.
  • The only other commit to touch this file, 3a62eb1 ("fix: migrate to WYRE-AI org", PR fix: migrate to WYRE-AI org (npm scope, ghcr namespace, registry) #1, merged 2026-08-25), changed exactly one line — project-url from orgs/wyre-technology/projects/1 to orgs/WYRE-AI/projects/1 — and left the broken mechanism untouched.

PR #1 was this repo's first-ever PR, which is what first triggered an issues/pull_request-activated workflow that had been broken since day one. The org transfer didn't break it; it just exposed a bug that was already there.

Fix

Replaced the body with the same reusable-workflow call already used and working across 30 sibling repos (verified via filename:add-to-project.yml org:WYRE-AI code search — 31 hits total, 30 correct + this one broken one):

jobs:
  call:
    uses: wyre-technology/.github/.github/workflows/auto-add-to-project.yml@c3314c1065f78adf905a815ad214c71266913771  # pinned (warden C-4) — bump via PR not in-place edit
    secrets: inherit

Verified byte-identical to action1-mcp, autotask-mcp, ninjaone-mcp, halopsa-mcp (and matches this repo's own MCP-server counterpart, WYRE-AI/ncentral-mcp, modulo a one-comment-punctuation variant there).

Note on project-url: the reusable workflow (wyre-technology/.github/.github/workflows/auto-add-to-project.yml) hardcodes project-url: https://github.com/orgs/wyre-technology/projects/1 internally — its workflow_call trigger takes no project-url input at all. None of the 30 working siblings pass one, including three other repos that live in the WYRE-AI org today (action1-mcp, ncentral-mcp, node-iqms, node-threatlocker) — they all resolve to the same shared wyre-technology project board regardless of which org the calling repo lives in. So this PR drops this repo's WYRE-AI-specific project-url (set by PR #1) rather than trying to preserve it — that's not a regression, it's matching the exact behavior every other working repo in this org already has.

Verification

  • diff against action1-mcp/.github/workflows/add-to-project.yml: no output (byte-identical).
  • Not merging this — leaving open for review.

View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

…oken pattern

The legacy pattern (actions/add-to-project@v1.0.2 with
secrets.ADD_TO_PROJECT_TOKEN) references a PAT secret that does not
exist in either wyre-technology or WYRE-AI. Replaced with the same
reusable-workflow call (GitHub App token minting, no static PAT) used
by all 30 sibling repos that already have this file working, including
this repo's own MCP-server counterpart (WYRE-AI/ncentral-mcp) and the
other two node-* client libraries that carry it (node-iqms,
node-threatlocker).

Root cause is NOT an org-transfer casualty: the fleet migrated off the
raw-token pattern onto the reusable workflow around May 2026, but this
repo was created 2026-07-03 (two months later) already carrying the
stale pattern in its very first commit. The org-transfer PR (#1,
2026-08-25) only updated project-url's value and never touched the
broken mechanism around it -- it was the repo's first-ever PR, which
is what first triggered the (already latently broken) workflow.

Matches the proven working pattern byte-for-byte: the reusable
workflow hardcodes its own project-url internally (no with: override
exists in its workflow_call inputs), so none of the 30 working
siblings -- including three other WYRE-AI-org repos -- pass one either.
This repo's legacy project-url (orgs/WYRE-AI/projects/1, set by PR #1)
is dropped for the same reason every other working sibling drops it.
@asachs01
asachs01 merged commit 8ff4bde into main Aug 28, 2026
4 checks passed
@asachs01
asachs01 deleted the fix/add-to-project-reusable-workflow branch August 28, 2026 00:25
github-actions Bot pushed a commit that referenced this pull request Aug 28, 2026
## [1.0.2](v1.0.1...v1.0.2) (2026-08-28)

### Bug Fixes

* use reusable auto-add-to-project workflow instead of stale raw-token pattern ([#2](#2)) ([8ff4bde](8ff4bde)), closes [#1](#1) [#1](#1)
@github-actions

Copy link
Copy Markdown

🎉 This PR is included in version 1.0.2 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant