By default, ghafk uses your gh login on GitHub. With a GitHub App, its
comments, labels and reviews show as <app>[bot].
-
Create a GitHub App under your account or your organization.
-
Turn off the webhook.
-
Give the app these repository permissions:
Permission Access Contents Read-only Issues Read and write Pull requests Read and write Metadata Read-only (the default) -
Generate a private key.
-
Install the app on the repositories that ghafk works. "All repositories" also includes each repository that you add later.
-
Save the App ID in
~/.ghafk/app. -
Save the key at
~/.ghafk/app.pem. Only you must be able to read it (mode0600or0400).
- For each repository, ghafk gets a short-lived token. The token can only access that repository, with the permissions above.
- ghafk still opens and merges pull requests with your login. Thus the work counts on your GitHub profile, and the app can review it.
Note
If you do not configure the app, ghafk uses your login. If ghafk cannot get a token, it writes one line to the log and uses your login.