Repository navigation
chore(ci): adopt putio-ci credential names - #91
Conversation
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: a3f878d2c5
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
Correctness of the release depends on the renamed release-environment secret and variable being configured in GitHub settings (not visible in the diff), and merging this change exercises the publish pipeline, so a human should confirm the out-of-band credential setup first.
Review effort: Balanced
Findings: 1
Open (1)
What changed in this PR
This is a CI/release-plumbing change that adopts the renamed putio-ci GitHub App credential names for the npm release pipeline. The rokit release job delegates to putdotio/.github's shared frontend-release-npm.yml; this PR re-pins that workflow to the commit that performs the credential rename and passes the renamed secret, then updates the distribution docs to match. I verified against the shared workflow at the pinned commit that PUTIO_CI_APP_PRIVATE_KEY is an accepted secret, PUTIO_CI_APP_CLIENT_ID is read as a vars.* value (with legacy fallbacks retained), and the minted token is the putio-ci installation token.
Changes:
- Re-pin the shared release workflow to
aebc5c23…and rename the passed secretPUTIO_RELEASE_BOT_PRIVATE_KEY→PUTIO_CI_APP_PRIVATE_KEY. - Update
docs/DISTRIBUTION.mdto documentPUTIO_CI_APP_CLIENT_ID/PUTIO_CI_APP_PRIVATE_KEYand theputio-ciinstallation token.
| File | Description |
|---|---|
.github/workflows/ci.yml |
Re-pins the shared release workflow and renames the forwarded release secret to PUTIO_CI_APP_PRIVATE_KEY. |
docs/DISTRIBUTION.md |
Updates required credential names and the installation-token name to the putio-ci naming. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Use the renamed putio-ci App credentials for releases.
PUTIO_CI_APP_PRIVATE_KEYthrough the compatible shared workflow, pinned to its merged commit.pnpm run verify,actionlint, andgit diff --checkpassed locally. No release or deployment was dispatched.Written by an agent (Codex, gpt-6-astra)