chore(deps): bump actions/create-github-app-token from 2.2.2 to 3.1.1#845
chore(deps): bump actions/create-github-app-token from 2.2.2 to 3.1.1#845dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [actions/create-github-app-token](https://github.com/actions/create-github-app-token) from 2.2.2 to 3.1.1. - [Release notes](https://github.com/actions/create-github-app-token/releases) - [Commits](actions/create-github-app-token@fee1f7d...1b10c78) --- updated-dependencies: - dependency-name: actions/create-github-app-token dependency-version: 3.1.1 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, have a team admin enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 1188d3b. Configure here.
| - name: Generate release token | ||
| id: app-token | ||
| uses: actions/create-github-app-token@fee1f7d63c2ff003460e3d139729b119787bc349 # v2 | ||
| uses: actions/create-github-app-token@1b10c78c7865c340bc4f6099eb2f838309f1e8c3 # v3.1.1 |
There was a problem hiding this comment.
Deprecated app-id parameter used with Client ID secret
Medium Severity
After bumping to v3.1.1, the workflow still passes secrets.RELEASE_APP_CLIENT_ID to the deprecated app-id parameter. The v3.1.0 release specifically added client-id as the replacement input for Client IDs and deprecated app-id. The secret name strongly indicates it contains a Client ID, which means the parameter should be client-id rather than app-id. While app-id still works as a deprecated fallback, this mismatch risks breakage in a future version and may emit deprecation warnings.
Reviewed by Cursor Bugbot for commit 1188d3b. Configure here.
PR Metrics
Updated Wed, 06 May 2026 19:51:40 GMT · run #1408 |


Bumps actions/create-github-app-token from 2.2.2 to 3.1.1.
Release notes
Sourced from actions/create-github-app-token's releases.
... (truncated)
Commits
1b10c78build(release): 3.1.1 [skip ci]07e2b76fix: improve error message when app identifier is empty (#362)ea01216ci: remove publish-immutable-action workflow (#361)7bd0371build(release): 3.1.0 [skip ci]e6bd4e6feat: addclient-idinput and deprecateapp-id(#353)076e948feat: update permission inputs (#358)3bbe07dfix(deps): bump p-retry from 7.1.1 to 8.0.0 (#357)28a99e3build(deps-dev): bump c8 from 10.1.3 to 11.0.04df5060build(deps-dev): bump open-cli from 8.0.0 to 9.0.04843c53build(deps-dev): bump the development-dependencies group with 3 updatesDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)Note
Medium Risk
Upgrades the GitHub App token generation step in the release workflow to a new major version, which could affect CI/release execution if inputs or runner requirements have changed.
Overview
Updates the
version-bump.ymlrelease workflow to useactions/create-github-app-tokenv3.1.1 (pinned SHA) instead of the previous v2 pin for generating the release GitHub App token.Reviewed by Cursor Bugbot for commit 1188d3b. Bugbot is set up for automated code reviews on this repo. Configure here.