Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 3 additions & 2 deletions .github/actions/notify-catalog/action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,10 +2,11 @@ name: Notify official plugin catalog
description: Request a complete central catalog reconciliation and return its accepted run.
inputs:
client-id:
description: Client ID of the organization-owned catalog GitHub App.
description: Client ID of the organization's Computer MCP Release Notifier GitHub App.
required: true
private-key:
description: Catalog App private key supplied from the authorized sender's Actions secret.
description:
Release Notifier App private key supplied from the authorized sender's Actions secret.
required: true
outputs:
run-url:
Expand Down
4 changes: 2 additions & 2 deletions docs/plugin-catalog.md
Original file line number Diff line number Diff line change
Expand Up @@ -182,7 +182,7 @@ and can deploy it without incrementing generation. A local generated file alone
anything. Publisher tests also run in read-only website CI, without contacting release sources.

The repository allows auto-merge. Only when the catalog changes, the central build job mints a
short-lived installation token for the organization's Computer MCP Automation GitHub App, which has
short-lived installation token for the organization's Computer MCP Updater GitHub App, which has
Contents and Pull requests write access and is installed only on this repository and the Homebrew
tap. Its client ID and private key are the `AUTOMATION_APP_CLIENT_ID` variable and
`AUTOMATION_APP_PRIVATE_KEY` secret. That token creates the signed proposal and opens and
Expand All @@ -202,7 +202,7 @@ short-lived installation token from its `client-id` and `private-key` inputs, an
`{"ref":"master"}` to the fixed official `pages.yml` workflow. It cannot supply releases, replace
policy or select another ref. It neither checks out nor executes the plugin package.

The organization-owned catalog GitHub App is installed only on
The organization's Computer MCP Release Notifier GitHub App is installed only on
`computer-mcp/computer-mcp.github.io`, with Actions write and mandatory Metadata read. Actions write
also permits other Actions administration in that repository; GitHub does not offer a
workflow-specific dispatch-only permission. The App has no website Contents write permission.
Expand Down
Loading