Skip to main content

Module manifest

Module manifest 

Source
Expand description

Registering the community’s GitHub App through the manifest flow (§5.7).

The bridge builds a manifest; the admin’s browser POSTs it to GitHub (a form whose manifest field is the JSON below) at the URL from registration_url; the admin approves; GitHub redirects to redirect_url with a one-time code; exchange_code trades it for the App’s id, private key and webhook secret. Nobody copies a key by hand.

The permission set is fixed here, not a parameter, so every community’s App asks for the same reviewed set. The manifest travels through the admin’s browser, where it could be altered, so exchange_code checks that the App GitHub actually registered holds nothing beyond these permissions and refuses the credentials otherwise.

GitHub’s manifest format cannot enable the OAuth device flow; the admin ticks “Enable Device Flow” on the App’s settings page once, or account linking reports device_flow_disabled.

Structs§

AppCredentials
What registering the App produced. Holds the App private key and the webhook and client secrets: zeroized on drop, never Debug-printed.
ManifestParams
Inputs to the manifest.

Constants§

APP_EVENTS
Webhook events for drift (§5.6), plus organization for members joining and leaving the org, pull_request / merge_group / check_run / check_suite so the bridge can post (and re-post, on a rerequest) the check where it runs it itself, and push for the Dependabot re-sign’s provenance ledger (RESIGN_EVENTS). installation events are always delivered to an App and need no subscription. Sorted.
APP_PERMISSIONS
The App’s permissions: repository Administration (write), Contents (write, for the bootstrap commit and for pushing re-signed Dependabot commits, §9), Variables (write), Metadata (read); organisation Members (read) and Administration (write). No secrets, Actions logs, code scanning or packages.
CHECK_EVENTS
The events the bridge-posted check is triggered by (see CHECK_PERMISSIONS).
CHECK_PERMISSIONS
What the bridge-posted check needs on an installation: the permissions and the event subscriptions. An App registered before these were in the manifest has neither until its settings are changed and each installation’s owner approves the change — until then the namespace keeps the in-repo Actions workflow.
RESIGN_EVENTS
The events the Dependabot re-sign needs (§9, “Dependabot re-sign bot”): push, the signed record of who moved each dependabot/* branch, from which the bridge decides whether a branch is Dependabot’s alone. GitHub delivers it under Contents, which the App already holds (write, for the bootstrap commit and the re-signed push). An App registered before push was in the manifest sees no pushes, so no branch is ever clean and nothing is re-signed until the owner subscribes it — failing safe.

Functions§

app_manifest
The manifest JSON.
check_ready
Whether an installation with granted permissions and events subscriptions can carry the bridge-posted check.
exchange_code
Exchange the redirect’s code for the App’s credentials (POST /app-manifests/{code}/conversions). The code is single-use and expires after an hour.
registration_url
Where the admin’s browser POSTs the manifest form: the org’s settings when org is given (the App is then owned by the org), the admin’s own otherwise. state comes back on the redirect; check it there.