From d4ac56c15564dbe2a20a68429391e0be92c53325 Mon Sep 17 00:00:00 2001 From: Svilen Stefanov Date: Thu, 24 Sep 2026 02:28:39 +0200 Subject: [PATCH] feat: retire license keys: drop license_key and llm: license Plans follow the GitHub account a run is charged to, and license keys stop validating at the key cutoff (design 10.5), so the action stops carrying them: no license_key input, no licence file staged, no `~codeboarding-license~` in the relay's or the preflight's bearer, and the tiers are hosted and byok only. A workflow still on `llm: license` is refused as `license_retired` with the one-word fix instead of `unknown_llm`. The dogfood workflows move to `llm: hosted`. Shipped as feat:, not feat!:, for the reason AGENTS.md gives for the llm change: v1 users must receive it on the moving tag. Co-Authored-By: Claude Opus 5.5 (1M context) --- .github/workflows/codeboarding-sync.yml | 3 +- .github/workflows/codeboarding.yml | 7 +- README.md | 45 ++++------ action.yml | 9 +- scripts/action/configure-auth.sh | 5 +- scripts/action/credential_check.py | 111 ++++++++---------------- scripts/action/run_meter.py | 13 +-- scripts/action/verify-credentials.sh | 7 -- scripts/oidc_relay.py | 15 +--- tests/test_action_auth.py | 68 ++------------- tests/test_action_inputs.py | 8 +- tests/test_llm_contract.py | 74 +++++----------- tests/test_oidc_relay.py | 12 +-- tests/test_run_meter.py | 13 +-- 14 files changed, 98 insertions(+), 292 deletions(-) diff --git a/.github/workflows/codeboarding-sync.yml b/.github/workflows/codeboarding-sync.yml index 2660515..4f1a303 100644 --- a/.github/workflows/codeboarding-sync.yml +++ b/.github/workflows/codeboarding-sync.yml @@ -142,8 +142,7 @@ jobs: with: mode: sync # CodeBoarding's own repositories run on the CodeBoarding plan. - llm: license - license_key: ${{ secrets.CODEBOARDING_LICENSE }} + llm: hosted sync_strategy: ${{ inputs.sync_strategy || 'push' }} force_full: ${{ inputs.force_full || false }} # App token authenticates the baseline push so the commit is attributed diff --git a/.github/workflows/codeboarding.yml b/.github/workflows/codeboarding.yml index 3495800..38240f8 100644 --- a/.github/workflows/codeboarding.yml +++ b/.github/workflows/codeboarding.yml @@ -111,8 +111,7 @@ jobs: - uses: ./ with: # Named, not inferred: the action refuses to guess where credentials come - # from, so every workflow says which of hosted / license / a provider it - # wants. CodeBoarding's own repositories run on the CodeBoarding plan. - llm: license - license_key: ${{ secrets.CODEBOARDING_LICENSE }} + # from, so every workflow says which of hosted / a provider it wants. + # CodeBoarding's own repositories run on the CodeBoarding plan. + llm: hosted github_token: ${{ steps.codeboarding-app-token-client.outputs.token || steps.codeboarding-app-token-app.outputs.token || github.token }} diff --git a/README.md b/README.md index f913867..838c669 100644 --- a/README.md +++ b/README.md @@ -52,7 +52,7 @@ jobs: steps: - uses: CodeBoarding/CodeBoarding-action@v1 with: - llm: hosted # or license, or a provider name -- see Authentication + llm: hosted # or a provider name -- see Authentication ``` Automatic runs review both draft and non-draft pull requests and update one sticky **CodeBoarding review** comment. Opening, reopening, or pushing a commit runs analysis; changing only the draft state does not. A trusted repository owner, member, or collaborator can comment `/codeboarding` to analyze the current PR head again, including on fork PRs; every command creates a new result comment. @@ -107,16 +107,11 @@ Every review comment ends with a machine-readable HTML comment, `