# \[ANN\] The TagBot GitHub App is deprecated in favour of the TagBot GitHub Action

**URL:** <https://discourse.julialang.org/t/ann-the-tagbot-github-app-is-deprecated-in-favour-of-the-tagbot-github-action/34344>\
**Category:** Tooling\
**Tags:** tagbot\
**Created:** [February 8, 2020, 12:52pm UTC](https://discourse.julialang.org/t/ann-the-tagbot-github-app-is-deprecated-in-favour-of-the-tagbot-github-action/34344 "2020-02-08T12:52:16Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![christopher-dG](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/christopher-dg/32/7387_2.png) [@christopher-dG](https://discourse.julialang.org/u/christopher-dG)\
**Post date:** [February 8, 2020, 12:52pm UTC](https://discourse.julialang.org/t/ann-the-tagbot-github-app-is-deprecated-in-favour-of-the-tagbot-github-action/34344/1 "2020-02-08T12:52:16Z")

</div>

TL;DR: Merge PRs that create a file called `.github/workflows/TagBot.yml` or create it yourself with these contents in all of your Julia package repositories:

```yml
name: TagBot
on:
  schedule:
    - cron: 0 * * * *
jobs:
  TagBot:
    runs-on: ubuntu-latest
    steps:
      - uses: JuliaRegistries/TagBot@v1
        with:
          token: ${{ secrets.GITHUB_TOKEN }}

```

* * *

### What’s happening

- The Julia TagBot GitHub App (the friendly robot first announced [here](https://discourse.julialang.org/t/ann-tagbot-creates-tags-and-releases-for-your-julia-packages-when-theyre-registered/23084) who creates your releases and then comments on registry PRs like [so](https://github.com/JuliaRegistries/General/pull/9071#issuecomment-583728398)) is being deprecated and will eventually cease to exist.
- Its successor is [TagBot as a GitHub Action](https://github.com/marketplace/actions/julia-tagbot), which requires you to add a file to your repositories.
- To ease this transition, pull requests will appear in your repositories adding the default configuration for you, if you had the App installed previously (you may have noticed a bunch of your repositories being forked, this is why).
- The GitHub App will add a deprecation notice to all of its comments, but continue to function normally for the time being, except it will ignore repositories that have the GitHub Action installed. I anticipate it’ll still be some months before I shut it down for good.

### What do I need to do?

Merge the pull request that the [JuliaTagBot user](https://github.com/JuliaTagBot) creates on your repository, or follow the instructions [here](https://github.com/marketplace/actions/julia-tagbot) to add the file yourself. There are a number of options that you can set, but the default minimal configuration is sufficient for most packages. You can also install the default configuration on all repositories in your user account or organization with [MassInstallAction.jl](https://github.com/bcbi/MassInstallAction.jl).

### Why move away from the GitHub App?

Moving to GitHub Actions has a few benefits:

- The new setup has more features and is more customizable by you.
- I no longer have to maintain any infrastructure.
- I no longer have access to your repositories through the GitHub App’s private key.
- You can now verify that the TagBot code running on your repositories is the same as what’s in the TagBot repository.

Anyways, let me know if you have any questions about this process. I expect PRs to start going up in a couple hours.

---

<div class="post-metadata">

**Author:** ![cpfiffer](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/cpfiffer/32/208747_2.png) [@cpfiffer](https://discourse.julialang.org/u/cpfiffer)\
**Post date:** [February 8, 2020, 2:54pm UTC](https://discourse.julialang.org/t/ann-the-tagbot-github-app-is-deprecated-in-favour-of-the-tagbot-github-action/34344/2 "2020-02-08T14:54:45Z")

</div>

Thanks for making and supporting an incredibly useful tool, and thanks for making this incredibly seamless!

---

<div class="post-metadata">

**Author:** ![tim.holy](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/tim.holy/32/52_2.png) [@tim.holy](https://discourse.julialang.org/u/tim.holy)\
**Post date:** [February 8, 2020, 3:27pm UTC](https://discourse.julialang.org/t/ann-the-tagbot-github-app-is-deprecated-in-favour-of-the-tagbot-github-action/34344/3 "2020-02-08T15:27:29Z")

</div>

Such wonderful support of your users! And until I checked the docs I didn’t realize this would support local registries. I’m excited to stop pushing those tags manually.

If I understand correctly this means it will be checking to see if new tag(s) are needed once per hour, right? And this doesn’t cost us (meaning any Julia organization) anything for compute time/internet bandwidth?

---

<div class="post-metadata">

**Author:** ![christopher-dG](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/christopher-dg/32/7387_2.png) [@christopher-dG](https://discourse.julialang.org/u/christopher-dG)\
**Post date:** [February 8, 2020, 3:32pm UTC](https://discourse.julialang.org/t/ann-the-tagbot-github-app-is-deprecated-in-favour-of-the-tagbot-github-action/34344/4 "2020-02-08T15:32:07Z")

</div>

> [@tim.holy](#):
>
> If I understand correctly this means it will be checking to see if new tag(s) are needed once per hour, right?

Correct.

> [@tim.holy](#):
>
> And this doesn’t cost us (meaning any Julia organization) anything for compute time/internet bandwidth?

As long as the packages are public, it’s free. For private repos, you get a certain number of minutes per month so I’d recommend reducing the frequency.

---

<div class="post-metadata">

**Author:** ![ccoffrin](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/ccoffrin/32/400_2.png) [@ccoffrin](https://discourse.julialang.org/u/ccoffrin)\
**Post date:** [February 8, 2020, 3:49pm UTC](https://discourse.julialang.org/t/ann-the-tagbot-github-app-is-deprecated-in-favour-of-the-tagbot-github-action/34344/5 "2020-02-08T15:49:36Z")

</div>

What amount of maintenance do you expect package developers will need to do on the `TagBot.yml` file?

---

<div class="post-metadata">

**Author:** ![christopher-dG](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/christopher-dg/32/7387_2.png) [@christopher-dG](https://discourse.julialang.org/u/christopher-dG)\
**Post date:** [February 8, 2020, 4:03pm UTC](https://discourse.julialang.org/t/ann-the-tagbot-github-app-is-deprecated-in-favour-of-the-tagbot-github-action/34344/6 "2020-02-08T16:03:52Z")

</div>

Zero, except for one exception that I know of:

- If you’re using GitHub Actions for your documentation deploys (or any other on-tag event): You need to add a different access token or SSH key to make those builds trigger to give you per-version hosted docs (a bit more info [here](https://github.com/JuliaRegistries/TagBot#personal-access-tokens)).

---

<div class="post-metadata">

**Author:** ![ccoffrin](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/ccoffrin/32/400_2.png) [@ccoffrin](https://discourse.julialang.org/u/ccoffrin)\
**Post date:** [February 8, 2020, 4:21pm UTC](https://discourse.julialang.org/t/ann-the-tagbot-github-app-is-deprecated-in-favour-of-the-tagbot-github-action/34344/7 "2020-02-08T16:21:06Z")

</div>

Do we have high confidence that Github won’t change the spec of the actions yml file?

---

<div class="post-metadata">

**Author:** ![christopher-dG](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/christopher-dg/32/7387_2.png) [@christopher-dG](https://discourse.julialang.org/u/christopher-dG)\
**Post date:** [February 8, 2020, 4:27pm UTC](https://discourse.julialang.org/t/ann-the-tagbot-github-app-is-deprecated-in-favour-of-the-tagbot-github-action/34344/8 "2020-02-08T16:27:07Z")

</div>

Well, I can’t speak for GitHub but IMO it’d be really dumb for them to do that after Actions has reached general availability. Although [they did change from HCL to YML](https://github.blog/changelog/2019-09-17-github-actions-will-stop-running-workflows-written-in-hcl/) during beta… I’m still doubtful that they’ll pull something like that again.

---

<div class="post-metadata">

**Author:** ![tim.holy](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/tim.holy/32/52_2.png) [@tim.holy](https://discourse.julialang.org/u/tim.holy)\
**Post date:** [February 8, 2020, 5:52pm UTC](https://discourse.julialang.org/t/ann-the-tagbot-github-app-is-deprecated-in-favour-of-the-tagbot-github-action/34344/9 "2020-02-08T17:52:09Z")

</div>

And presumably we could do maintenance via the `MassInstallAction.jl` you linked above?

(Speaking as someone who currently has 114 TagBot-related emails in my inbox…)

---

<div class="post-metadata">

**Author:** ![giordano](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/giordano/32/2166_2.png) [@giordano](https://discourse.julialang.org/u/giordano)\
**Post date:** [February 8, 2020, 6:29pm UTC](https://discourse.julialang.org/t/ann-the-tagbot-github-app-is-deprecated-in-favour-of-the-tagbot-github-action/34344/10 "2020-02-08T18:29:01Z")

</div>

Out of curiosity, does this trigger a download of Julia every hour?

---

<div class="post-metadata">

**Author:** ![dilumaluthge](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/dilumaluthge/32/29283_2.png) [@dilumaluthge](https://discourse.julialang.org/u/dilumaluthge)\
**Post date:** [February 8, 2020, 6:35pm UTC](https://discourse.julialang.org/t/ann-the-tagbot-github-app-is-deprecated-in-favour-of-the-tagbot-github-action/34344/11 "2020-02-08T18:35:05Z")

</div>

> [@giordano](#):
>
> Out of curiosity, does this trigger a download of Julia every hour?

I believe it does, although it should go through a cache and thus not coar us money. @staticfloat

---

<div class="post-metadata">

**Author:** ![oheil](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/oheil/32/220745_2.png) [@oheil](https://discourse.julialang.org/u/oheil)\
**Post date:** [February 8, 2020, 6:50pm UTC](https://discourse.julialang.org/t/ann-the-tagbot-github-app-is-deprecated-in-favour-of-the-tagbot-github-action/34344/12 "2020-02-08T18:50:45Z")

</div>

Thanks for all the work!

---

<div class="post-metadata">

**Author:** ![fredrikekre](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/fredrikekre/32/1688_2.png) [@fredrikekre](https://discourse.julialang.org/u/fredrikekre)\
**Post date:** [February 8, 2020, 7:43pm UTC](https://discourse.julialang.org/t/ann-the-tagbot-github-app-is-deprecated-in-favour-of-the-tagbot-github-action/34344/13 "2020-02-08T19:43:48Z")

</div>

> [@dilumaluthge](#):
>
> > Out of curiosity, does this trigger a download of Julia every hour?
> 
> I believe it does, although it should go through a cache and thus not cost us very much. @staticfloat

TagBot is implemented in Python.

---

<div class="post-metadata">

**Author:** ![dilumaluthge](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/dilumaluthge/32/29283_2.png) [@dilumaluthge](https://discourse.julialang.org/u/dilumaluthge)\
**Post date:** [February 8, 2020, 8:02pm UTC](https://discourse.julialang.org/t/ann-the-tagbot-github-app-is-deprecated-in-favour-of-the-tagbot-github-action/34344/14 "2020-02-08T20:02:23Z")

</div>

> [@fredrikekre](#):
>
> TagBot is implemented in Python.

Ah. Well I guess that renders the “Julia downloads” point moot.

It does seem like a missed opportunity to eat our own dog food.

---

<div class="post-metadata">

**Author:** ![tim.holy](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/tim.holy/32/52_2.png) [@tim.holy](https://discourse.julialang.org/u/tim.holy)\
**Post date:** [February 8, 2020, 8:27pm UTC](https://discourse.julialang.org/t/ann-the-tagbot-github-app-is-deprecated-in-favour-of-the-tagbot-github-action/34344/15 "2020-02-08T20:27:59Z")

</div>

…but not getting charged for downloads has its virtues…

---

<div class="post-metadata">

**Author:** ![dilumaluthge](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/dilumaluthge/32/29283_2.png) [@dilumaluthge](https://discourse.julialang.org/u/dilumaluthge)\
**Post date:** [February 8, 2020, 8:30pm UTC](https://discourse.julialang.org/t/ann-the-tagbot-github-app-is-deprecated-in-favour-of-the-tagbot-github-action/34344/16 "2020-02-08T20:30:01Z")

</div>

> [@tim.holy](#):
>
> …but not getting charged for downloads has its virtues…

For sure. But if I understand correctly, the caching layer that GiHub Actions will hit when it downloads Julia means that we don’t actually pay every time a GitHub Action downloads Julia. At least, I think that’s correct. @viralbshah and @staticfloat explained this on Slack a while back, so they can correct me if I am mistaken.

---

<div class="post-metadata">

**Author:** ![dilumaluthge](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/dilumaluthge/32/29283_2.png) [@dilumaluthge](https://discourse.julialang.org/u/dilumaluthge)\
**Post date:** [February 8, 2020, 8:35pm UTC](https://discourse.julialang.org/t/ann-the-tagbot-github-app-is-deprecated-in-favour-of-the-tagbot-github-action/34344/17 "2020-02-08T20:35:02Z")

</div>

The best solution will be for us to get Julia installed into the default virtual environment for GitHub Actions.

Here is the issue to track:

[https://github.com/actions/virtual-environments/issues/271](https://github.com/actions/virtual-environments/issues/271)

It would be great to get more `+ 1`s, thumbs up 👍, and comments in support of that issue.

---

<div class="post-metadata">

**Author:** ![rdeits](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/rdeits/32/286_2.png) [@rdeits](https://discourse.julialang.org/u/rdeits)\
**Post date:** [February 8, 2020, 8:42pm UTC](https://discourse.julialang.org/t/ann-the-tagbot-github-app-is-deprecated-in-favour-of-the-tagbot-github-action/34344/18 "2020-02-08T20:42:46Z")

</div>

Uh, I just merged several dozen PRs by hand, and now I’m getting approximately one email every 30 minutes for each of several dozen packages. It looks like TagBot fails and sends an email every half hour for every Julia project that doesn’t have a Project.toml?? How do I make this stop?

---

<div class="post-metadata">

**Author:** ![dilumaluthge](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/dilumaluthge/32/29283_2.png) [@dilumaluthge](https://discourse.julialang.org/u/dilumaluthge)\
**Post date:** [February 8, 2020, 8:43pm UTC](https://discourse.julialang.org/t/ann-the-tagbot-github-app-is-deprecated-in-favour-of-the-tagbot-github-action/34344/19 "2020-02-08T20:43:31Z")

</div>

> [@rdeits](#):
>
> Uh, I just merged several dozen PRs by hand, and now I’m getting approximately one email every 30 minutes for each of several dozen packages. It looks like TagBot fails and sends an email every half hour for every Julia project that doesn’t have a Project.toml?? How do I make this stop?

I am also getting many notifications about failures.

---

<div class="post-metadata">

**Author:** ![rdeits](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/rdeits/32/286_2.png) [@rdeits](https://discourse.julialang.org/u/rdeits)\
**Post date:** [February 8, 2020, 8:46pm UTC](https://discourse.julialang.org/t/ann-the-tagbot-github-app-is-deprecated-in-favour-of-the-tagbot-github-action/34344/20 "2020-02-08T20:46:17Z")

</div>

Ok, well, I’ve turned off all of my GitHub Actions notifications globally, so hopefully that will stop the flood. But that doesn’t seem like a great solution.

[Next page](https://discourse.julialang.org/t/ann-the-tagbot-github-app-is-deprecated-in-favour-of-the-tagbot-github-action/34344.md?page=2)
