fix: replace stale raw-token add-to-project workflow with reusable App-token pattern - #2
Merged
Merged
Conversation
…oken pattern The legacy pattern (actions/add-to-project@v1.0.2 with secrets.ADD_TO_PROJECT_TOKEN) references a PAT secret that does not exist in either wyre-technology or WYRE-AI. Replaced with the same reusable-workflow call (GitHub App token minting, no static PAT) used by all 30 sibling repos that already have this file working, including this repo's own MCP-server counterpart (WYRE-AI/ncentral-mcp) and the other two node-* client libraries that carry it (node-iqms, node-threatlocker). Root cause is NOT an org-transfer casualty: the fleet migrated off the raw-token pattern onto the reusable workflow around May 2026, but this repo was created 2026-07-03 (two months later) already carrying the stale pattern in its very first commit. The org-transfer PR (#1, 2026-08-25) only updated project-url's value and never touched the broken mechanism around it -- it was the repo's first-ever PR, which is what first triggered the (already latently broken) workflow. Matches the proven working pattern byte-for-byte: the reusable workflow hardcodes its own project-url internally (no with: override exists in its workflow_call inputs), so none of the 30 working siblings -- including three other WYRE-AI-org repos -- pass one either. This repo's legacy project-url (orgs/WYRE-AI/projects/1, set by PR #1) is dropped for the same reason every other working sibling drops it.
|
🎉 This PR is included in version 1.0.2 🎉 The release is available on:
Your semantic-release bot 📦🚀 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Root cause
add-to-project.ymlused the legacy raw-token pattern:secrets.ADD_TO_PROJECT_TOKENdoes not exist in eitherwyre-technologyorWYRE-AI— the fleet migrated off this raw-PAT pattern onto a reusable workflow that mints a short-lived GitHub App token instead, back around May 2026.This is NOT an org-transfer casualty, and specifically not the same failure family as the GHCR-package-visibility or
GHPKG_READ_TOKENorg-transfer issues seen on other repos. Those are carry-over gaps from moving a previously-working repo between orgs. This bug is different: it has been latent since this repo's creation.Confirmed via
git log:7abb53e(2026-07-03) already scaffoldedadd-to-project.ymlwith the legacysecrets.ADD_TO_PROJECT_TOKENpattern — two months after the fleet-wide migration to the reusable workflow.3a62eb1("fix: migrate to WYRE-AI org", PR fix: migrate to WYRE-AI org (npm scope, ghcr namespace, registry) #1, merged 2026-08-25), changed exactly one line —project-urlfromorgs/wyre-technology/projects/1toorgs/WYRE-AI/projects/1— and left the broken mechanism untouched.PR #1 was this repo's first-ever PR, which is what first triggered an
issues/pull_request-activated workflow that had been broken since day one. The org transfer didn't break it; it just exposed a bug that was already there.Fix
Replaced the body with the same reusable-workflow call already used and working across 30 sibling repos (verified via
filename:add-to-project.yml org:WYRE-AIcode search — 31 hits total, 30 correct + this one broken one):Verified byte-identical to
action1-mcp,autotask-mcp,ninjaone-mcp,halopsa-mcp(and matches this repo's own MCP-server counterpart,WYRE-AI/ncentral-mcp, modulo a one-comment-punctuation variant there).Note on
project-url: the reusable workflow (wyre-technology/.github/.github/workflows/auto-add-to-project.yml) hardcodesproject-url: https://github.com/orgs/wyre-technology/projects/1internally — itsworkflow_calltrigger takes noproject-urlinput at all. None of the 30 working siblings pass one, including three other repos that live in theWYRE-AIorg today (action1-mcp,ncentral-mcp,node-iqms,node-threatlocker) — they all resolve to the same sharedwyre-technologyproject board regardless of which org the calling repo lives in. So this PR drops this repo'sWYRE-AI-specificproject-url(set by PR #1) rather than trying to preserve it — that's not a regression, it's matching the exact behavior every other working repo in this org already has.Verification
diffagainstaction1-mcp/.github/workflows/add-to-project.yml: no output (byte-identical).Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.