Files
hermes-agent/.github
teknium1 c3021aff0d ci(skills-index): re-mint the App token before the catalog stars probe; keep fetched_at honest on failure
The `Probe plugin catalog stars` step reused the GitHub App installation token
minted at job start. That token lives 1 h; `build_skills_index.py` (the step
before it) has walked ClawHub for 60-85 min since Sep 17, so every scheduled
probe since Sep 18 ran on an expired token and logged
`GraphQL probe failed (HTTP Error 401: Unauthorized); keeping previous counts`.
114 of the 213 catalog repos ended up without a star count and the "Most
starred" default sort fell to alphabetical for half the catalog.

Run-log evidence (job step timestamps; `gh run view --json jobs` + job logs):
  run 35569229751 (Sep 21): mint 06:36:52Z -> probe 08:01:50Z (85 min) -> 401,
      "Probed 213 repos ... wrote 99 star counts"
  run 35426522555 (Sep 19): mint 06:24:52Z -> probe 07:39:59Z (75 min) -> 401
  run 35133575877 (Sep 16, last success): mint 18:18:39Z -> probe 18:40:12Z
      (21 min) -> "Probed 100 repos ... wrote 100 star counts"

Fix: a second `./.github/actions/get-app-token` step (`probe-token`)
immediately before the probe; the probe reads that token. Ordering stays (the
probe does not depend on the walk, but the artifact upload wants both files
and the step comment already documents the walk timing).

Freshness: `main()` stamped `fetched_at = now` whenever the written map
differed from the previous one, so a FAILED probe still moved the timestamp
forward and the catalog footer read "popularity ranking as of <today>" over
Sep-16 counts (live `plugin-stars.json`: fetched_at 2026-09-21 with Sep-16
data). `probe_stars` now returns `(stars, probed)`; `fetched_at` advances only
when GitHub actually answered, otherwise the previous timestamp is kept, a
`:⚠️:` names how many catalog repos have no count, and the summary line
says "Probe failed; wrote N cached star counts (as of <ts>)" instead of
"Probed N repos".

Local repro (3 catalog repos, cache from Sep 16 with 2 of them, GraphQL 401):
  before: fetched_at restamped to now; "Probed 3 repos ... wrote 2 star counts"
  after:  fetched_at stays 2026-09-16T18:40:16+00:00; ":⚠️:plugin star
          probe failed; reused 2 cached counts from 2026-09-16..., 1 of 3
          catalog repos have no star count"

Not taken from #118129: the per-repo REST fallback and the payload-shape
validation. The transport was never the problem (the same expired token 401s
on REST too), and one GraphQL request per run is the rate-limit rule this
script documents.

Fixes #118113
credit: @fangliquanflq #118129 (honest fetched_at on a failed probe + ::warning; slim redo)
2026-09-21 23:31:02 -07:00
..