Skip to content

Site build calls the GitHub API (via astro-contributors) and gets rate-limited #1753

Description

Problem

The frontend build makes live calls to api.github.com while it renders pages. The build shouldn't depend on outside network services: the calls can fail, they make the output non-deterministic, and they slow down or break builds on shared CI agents.

src/frontend/src/content/docs/community/contributors.mdx uses <ContributorList> from the astro-contributors package for five repos:

  • microsoft/aspire
  • microsoft/aspire-samples
  • CommunityToolkit/Aspire
  • microsoft/aspire.dev
  • microsoft/dcp

When the page renders, the package calls https://api.github.com/repos/{repo}/contributors?per_page=100&page=N. It only authenticates if PUBLIC_GITHUB_TOKEN is set. Our internal Azure DevOps build (Aspire.Dev-Build, macOS hosted agents) doesn't set it, so the calls are anonymous. On shared agent IPs they hit GitHub's anonymous rate limit and return 403 Forbidden.

The package catches the error and returns an empty list. The Contributors page is built and deployed with no contributors, and this happens in every language version of the page.

Evidence

From the Run Aspire Publish step of internal build 3087220 (and the earlier build 3086870, which has 42 of the same errors):

[error]  /src/util/getContributors.ts
         Request to fetch endpoint failed. Reason: Bad response for https://api.github.com/repos/microsoft/aspire/contributors?per_page=100&page=1 (403): Forbidden
         Message: undefined

There are 41 of these per build: 5 repos × each language version of the page.

Proposed fix

Remove all live GitHub API calls from the build:

  • Generate the contributor data ahead of time with a script, similar to the existing update:release-contributors script and the pre-generated data used by GitHubRepoStats. Commit it as JSON under src/frontend/src/data/, and refresh it on a schedule or by hand.
  • Replace astro-contributors' <ContributorList> with a component that renders from that JSON, and remove the dependency if nothing else uses it.
  • Optionally, add a guard (a CI check or lint) so new build-time requests to api.github.com are caught.

Setting PUBLIC_GITHUB_TOKEN is not the preferred fix. The build would still make network calls, and a PUBLIC_* variable can end up in the browser code if anything reads it on the client.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

No labels
No labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions