ci: migrate cross-repo dispatch senders to workflow_dispatch (actions:write) (#21648)

# Introduction
Getting rid of the fine grained PAT used to dispatch to internal
repositories.
Repo dispatch requires the contents write permissions which is too wide
for such use
Refactored all senders and target to pass through a workflow dispatch
instead
Creating a centralize app that forges a token with actions: write only
provided permissions to mitigate any token exfiltrations
This commit is contained in:
Paul Rastoin
2026-06-16 15:18:43 +02:00
committed by GitHub
parent 1e8169ca3e
commit d5c7b735d2
15 changed files with 268 additions and 118 deletions
+13 -2
View File
@@ -151,9 +151,20 @@ jobs:
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
- name: Mint twenty-infra dispatch token
id: app-token
if: github.event_name != 'pull_request' && steps.check_changes.outputs.changes_detected == 'true'
uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0
with:
client-id: ${{ vars.TWENTY_WORKFLOW_DISPATCHER_CLIENT_ID }}
private-key: ${{ secrets.TWENTY_WORKFLOW_DISPATCHER_PRIVATE_KEY }}
owner: twentyhq
repositories: twenty-infra
permission-actions: write
- name: Trigger i18n automerge
if: github.event_name != 'pull_request' && steps.check_changes.outputs.changes_detected == 'true'
env:
GH_TOKEN: ${{ secrets.TWENTY_INFRA_TOKEN }}
GH_TOKEN: ${{ steps.app-token.outputs.token }}
run: |
gh api repos/twentyhq/twenty-infra/dispatches -f event_type=i18n-pr-ready
gh workflow run automerge-i18n.yaml --repo twentyhq/twenty-infra --ref main