Skip to content

Supply the GitHub token for OctoJPack public sources - #6

Merged
Llewellynvdm merged 2 commits into
mainfrom
fix/octojpack-api-token
Sep 29, 2026
Merged

Llewellynvdm merged 2 commits into
mainfrom
fix/octojpack-api-token

Conversation

@Llewellynvdm

@Llewellynvdm Llewellynvdm commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

The component release completed its tag, update entry and OctoShoom checksum, then OctoJPack stopped with We require (.global.token). The workflow supplied an empty VDM_GLOBAL_TOKEN because GIT_TOKEN was unset. The .octojpack format is valid; the error is the native loader's fallback for a missing environment token.

Use ${{ secrets.GIT_TOKEN || github.token }} for VDM_GLOBAL_TOKEN. The built-in contents:read token lets OctoJPack discover public source tags; an explicit secret remains an override. Git User still configures SSH publication once. The release fix is one line: no configuration placeholders, added scripts or shared-engine changes.

The installed workflows also exposed their old console pin's major-version coupling against component 1.0.0. Both now pin the verified independent-version installer fix at eab466cfb51c9ef51bdb2f18431c2e2fcdafbc3b from joomengine/mcp_plugin#4. Update release/recovery documentation and record both fixes in the pending changelogs.

Validation at 8a1a647:

  • actionlint passes; all 22 release metadata checks pass.
  • Actual upstream OctoJPack configuration functions reproduce the missing-token error, then accept the unchanged configuration with a nonempty synthetic environment token. All three source entries select latest tags. No package build or push was run locally.
  • PHP 8.3/8.4 contracts: passed.
  • Installed Joomla matrix: all four PHP 8.3/8.4 × MySQL/PostgreSQL jobs passed, including the corrected console plugin's 27 assertions and upgrade/uninstall.
  • JCB golden-image acceptance: passed, including native installation, administrator/MCP, HTTP ACL, stdio CRUD, JCB inventory, package/compiler jobs, ZIP downloads, remote HTTPS bridge and upgrade/uninstall.

Fixes https://github.com/joomengine/mcp_component/actions/runs/36543905015/job/109325588960.

After merging both PRs, publish the console installer fix through its next-version workflow, then start a NEW component Release run from main with existing version 1.0.0. This uses the corrected workflow while preserving the existing component tag/checksum. Re-running the old failed job uses its original workflow. A successful release run is still required to verify package publication credentials; no release was run by this PR.

@Llewellynvdm
Llewellynvdm marked this pull request as ready for review September 29, 2026 08:56
@Llewellynvdm
Llewellynvdm merged commit adb2bbd into main Sep 29, 2026
7 checks passed
@Llewellynvdm
Llewellynvdm deleted the fix/octojpack-api-token branch September 29, 2026 09:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant