Conversation
…unner defaults - #264 (PLT-4224) replaced secrets.GH_TOKEN with secrets.JENKINS_PAT_TOKEN inside six workflow_call workflows, but none of them declare JENKINS_PAT_TOKEN, so it resolves to an empty string for callers passing secrets explicitly. Restore secrets.GH_TOKEN there; callers still pass JENKINS_PAT_TOKEN as GH_TOKEN, as #264's README and template changes describe. - frontend-pr-workflow runner/e2e-runner defaults were '[ci-universal-scale-set]', which isn't valid JSON, so fromJSON() fails and callers relying on the default never get their build/test jobs created. Quote them like the deploy workflow does. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019tUHRKTe2YrU4YwTbKzXPH
Tested against a real caller: chiefI ran chief's CI in a throwaway draft PR, Typeform/chief#2161, on two refs of this repo. chief passes
Why
|
✅ Security Analysis ResultsNo security issues found. 7 files reviewed.
|
|
LGTM from the PLT-4224 / migration side. This matches the callee handoff bug we hit after the early DX batch: #264 renamed secrets.GH_TOKEN → secrets.JENKINS_PAT_TOKEN inside workflow_call callees, but the declared input is still GH_TOKEN. Callers (e.g. chief) correctly pass GH_TOKEN: ${{ secrets.JENKINS_PAT_TOKEN }}; the callee must keep reading secrets.GH_TOKEN. We later encoded that restore in PLT-4314+ batches. #270 is the right fix for the shared workflows that #264 broke. Please merge before moving v1. Also +1 on the runner default JSON fix ('["ci-..."]'). |
Two fixes for bugs that affect callers of the shared workflows. Both are small, and the first one needs to land before
v1is moved again.1. Reusable workflows use an undeclared secret (unreleased, from #264)
#264 (PLT-4224) replaced
secrets.GH_TOKENwithsecrets.JENKINS_PAT_TOKENinside sixworkflow_callworkflows:frontend-pr-workflow.ymlfrontend-deploy-workflow.ymlfrontend-library-pr-release-workflow.ymlgo-lint-workflow.yamlgraphql-generate-persisted-operations.ymlreusable-workflows/frontend-pr-workflow/workflow.ymlNone of them declare
JENKINS_PAT_TOKENunderon.workflow_call.secrets, so for any caller that passes secrets explicitly it resolves to an empty string. That includes the pattern #264's own README shows:GH_TOKEN: ${{ secrets.JENKINS_PAT_TOKEN }}. Installs from GitHub Packages, Jarvis setup and checkouts that use the token would then fail.This PR puts
secrets.GH_TOKENback in those six files. Each file is restored to its state just before #264, since #264 is the only commit that has touched them since. #264's caller-side changes, inworkflow-templates/*and the READMEs, are kept: callers keep passingJENKINS_PAT_TOKENin asGH_TOKEN.How this fits the PLT-4224 migration (not a revert)
The move from the org secret
GH_TOKENtoJENKINS_PAT_TOKEN(announcement) happens on the caller side, and that's unchanged here. Inside a reusable workflow,secrets.Xonly holds what's declared underon.workflow_call.secretsand passed in by the caller. The declared input isGH_TOKEN, so inside these workflowssecrets.GH_TOKENis the name of that input. It isn't the org secret. Callers already pass the new secret into it:GH_TOKEN: ${{ secrets.JENKINS_PAT_TOKEN }}(migrated)GH_TOKEN: ${{ secrets.GH_TOKEN }}(not yet migrated)None of them use
secrets: inherit, sosecrets.JENKINS_PAT_TOKENis empty inside these workflows, including for the callers that have already migrated. Once all callers passJENKINS_PAT_TOKEN, the orgGH_TOKENsecret can be deprecated as planned. If you'd like the input itself renamed, that's a breaking change for callers and needs a coordinated follow-up: declare aJENKINS_PAT_TOKENinput, usesecrets.JENKINS_PAT_TOKEN || secrets.GH_TOKENduring the transition, then dropGH_TOKEN.2. Invalid JSON in the
frontend-pr-workflowrunner defaultsrunnerdefaulted to'[ci-universal-scale-set]', ande2e-runnerto'[ci-e2e-scale-set]'. Neither is valid JSON, sofromJSON()fails and the jobs that use them are never created. Callers only work if they override the value; for exampledemo-apppasses'["ci-universal-scale-set"]'.frontend-packagesrelied on the default, and all 64 of itsPRruns failed with no Build or Unit Tests jobs. The deploy and library workflows already quote their defaults. This PR does the same here, and fixes the README examples.Verified:
frontend-packagesPR #32 ran green on a commit that includes this fix.🤖 Generated with Claude Code
https://claude.ai/code/session_019tUHRKTe2YrU4YwTbKzXPH