feat(accounts): offer a repository's immutable name in the trust form - #614
Merged
Merged
Conversation
GitHub signs tokens for repositories created after July 2026 with immutable subjects, repo:owner@id/repo@id, and a trust has to match that form exactly, which nobody can type from memory. When the Repository field holds owner/repo, the form asks GitHub's public API for the repository's ids once typing stops and offers the immutable name with a button that puts it in the field. A repository the API can't see, private or missing, gets the gh command that prints the name instead. Whether a repository's tokens actually carry the immutable form is a setting only its admins can read, so the form offers the name rather than switching to it. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
Contributor
|
Claude finished @alukach's task in 15s —— View job ✅ No blocking issues — safe to merge. I read the diff for
Simplify (ponytail)Nothing worth cutting. The hook is small, the regex guards the shell command, and there is no new dependency. DocsThe PR description covers this. It names ADR-014 in data.source.coop and says why it still holds, and it points to the "coming soon" GitHub Actions section of docs.source.coop#37. Nothing is missing. 💰 Estimated review cost: $0.13 · 0m15s · 4 turns |
The trust form says a repository may need its immutable name without saying what that is or which repositories get it. GitHub's changelog says both: the owner@id/repo@id subject, the default for repositories created, renamed or transferred after July 15, 2026, and the opt-in for older ones. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
alukach
added a commit
that referenced
this pull request
Oct 2, 2026
…615) CLAUDE.md told agents to build Storybook preview links as `source-coop-ui-git-<branch>-radiantearth.vercel.app`. Vercel caps a hostname label at 63 characters and truncates long branch names with a hash suffix, so for `feat/github-immutable-repository-lookup` ([#614](#614)) the guessed host doesn't resolve; the real one is `source-coop-ui-git-feat-github-immutable-re-82950d-radiantearth.vercel.app`. The Vercel bot comment carries the real host, but only after the PR is open — too late for the description written when it's created. So CLAUDE.md now gives a shell snippet that computes the host from the branch: `<project>-git-<slug>-radiantearth` when that fits in 63 characters, otherwise `<project>-git-<slug>` cut to 43 characters, then the first six hex characters of `sha256("git-" + <raw branch> + <project>)`, then `-radiantearth`. It also says to check the links against the bot comment once the PR is open. ## Testing Compared the snippet's output with the `source-coop-ui` host in the Vercel bot comment on the last 40 PRs: 39 match. The one miss, [#602](#602), is from a fork, which Vercel names `fork-<owner>-<branch>`; the snippet doesn't handle forks. Ran the snippet as written under bash and zsh for a short branch and a long (truncated) one. No UI, docs.source.coop or data-proxy ADR impact: this only changes contributor guidance in this repo. 🤖 Generated with [Claude Code](https://claude.com/claude-code) --------- Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
GitHub signs Actions tokens for repositories created after July 2026 (and any that opted in) with immutable subjects,
repo:owner@id/repo@id:…, and a service account's trust has to match that form exactly. Nobody knows their repository's numeric ids, so today the trust form takesowner/repo, the exchange is refused, and the uniform refusal doesn't say why. This came up on the first real GitHub Actions run against staging:alukach/source-coop-upload-testis new, so its tokens sayrepo:alukach@897290/source-coop-upload-test@1400565438:ref:refs/heads/main. Part of #491.What
GithubWorkflowFields, the fields behind both the create form and the "Trust a GitHub workflow" dialog:owner/repo, the form askshttps://api.github.com/repos/{owner}/{repo}once typing stops (400 ms) and offers the immutable name,octocat@583231/Hello-World@1296269, with Use it, which puts it in the field. The names come from GitHub's answer, so their case is GitHub's too.gh api repos/{owner}/{repo} --jq '"\(.owner.login)@\(.owner.id)/\(.name)@\(.id)"'. Run against the upload-test repository it printsalukach@897290/source-coop-upload-test@1400565438.Decisions to flag:
actions/oidc/customization/subsetting, which only its admins can read, even on a public repository. The creation date would only be a guess, so the form names the July 2026 default and leaves the choice to the user.ghone-liner covers it for anyone who can already see the repository.Stories
On this branch's deploy:
GithubWorkflowFields› PublicRepository: https://source-coop-ui-git-feat-github-immutable-re-82950d-radiantearth.vercel.app/?path=/story/features-service-accounts-githubworkflowfields--public-repository (asks GitHub for real, so it showsoctocat/Hello-World's actual ids)GithubWorkflowFields› PrivateRepository: https://source-coop-ui-git-feat-github-immutable-re-82950d-radiantearth.vercel.app/?path=/story/features-service-accounts-githubworkflowfields--private-repositoryTesting
GithubWorkflowFields.test.tsx(new,fetchmocked): a public repository's immutable name is offered and Use it sends it throughonChange; a 404 shows theghcommand; a value already immutable isn't looked up.src/stories.smoke.test.tsx: 193 pass, the two new stories included.npm run type-checkandnext linton the changed files are clean.ghcommand was run againstalukach/source-coop-upload-testand prints its token's subject prefix.Docs and ADRs
Checked ADR-014 (source-cooperative/data.source.coop): it says a trust names a subject exactly, in either form, and this changes only how the form helps fill one in, so it still holds. docs.source.coop: the automated-access guide (source-cooperative/docs.source.coop#37) has its GitHub Actions section marked "coming soon", so no existing page describes this field. That section should mention the immutable form when it's written.
🤖 Generated with Claude Code