Problem
The frontend build makes live calls to api.github.com while it renders pages. The build shouldn't depend on outside network services: the calls can fail, they make the output non-deterministic, and they slow down or break builds on shared CI agents.
src/frontend/src/content/docs/community/contributors.mdx uses <ContributorList> from the astro-contributors package for five repos:
microsoft/aspire
microsoft/aspire-samples
CommunityToolkit/Aspire
microsoft/aspire.dev
microsoft/dcp
When the page renders, the package calls https://api.github.com/repos/{repo}/contributors?per_page=100&page=N. It only authenticates if PUBLIC_GITHUB_TOKEN is set. Our internal Azure DevOps build (Aspire.Dev-Build, macOS hosted agents) doesn't set it, so the calls are anonymous. On shared agent IPs they hit GitHub's anonymous rate limit and return 403 Forbidden.
The package catches the error and returns an empty list. The Contributors page is built and deployed with no contributors, and this happens in every language version of the page.
Evidence
From the Run Aspire Publish step of internal build 3087220 (and the earlier build 3086870, which has 42 of the same errors):
[error] /src/util/getContributors.ts
Request to fetch endpoint failed. Reason: Bad response for https://api.github.com/repos/microsoft/aspire/contributors?per_page=100&page=1 (403): Forbidden
Message: undefined
There are 41 of these per build: 5 repos × each language version of the page.
Proposed fix
Remove all live GitHub API calls from the build:
- Generate the contributor data ahead of time with a script, similar to the existing
update:release-contributors script and the pre-generated data used by GitHubRepoStats. Commit it as JSON under src/frontend/src/data/, and refresh it on a schedule or by hand.
- Replace
astro-contributors' <ContributorList> with a component that renders from that JSON, and remove the dependency if nothing else uses it.
- Optionally, add a guard (a CI check or lint) so new build-time requests to
api.github.com are caught.
Setting PUBLIC_GITHUB_TOKEN is not the preferred fix. The build would still make network calls, and a PUBLIC_* variable can end up in the browser code if anything reads it on the client.
Problem
The frontend build makes live calls to
api.github.comwhile it renders pages. The build shouldn't depend on outside network services: the calls can fail, they make the output non-deterministic, and they slow down or break builds on shared CI agents.src/frontend/src/content/docs/community/contributors.mdxuses<ContributorList>from theastro-contributorspackage for five repos:microsoft/aspiremicrosoft/aspire-samplesCommunityToolkit/Aspiremicrosoft/aspire.devmicrosoft/dcpWhen the page renders, the package calls
https://api.github.com/repos/{repo}/contributors?per_page=100&page=N. It only authenticates ifPUBLIC_GITHUB_TOKENis set. Our internal Azure DevOps build (Aspire.Dev-Build, macOS hosted agents) doesn't set it, so the calls are anonymous. On shared agent IPs they hit GitHub's anonymous rate limit and return403 Forbidden.The package catches the error and returns an empty list. The Contributors page is built and deployed with no contributors, and this happens in every language version of the page.
Evidence
From the
Run Aspire Publishstep of internal build 3087220 (and the earlier build 3086870, which has 42 of the same errors):There are 41 of these per build: 5 repos × each language version of the page.
Proposed fix
Remove all live GitHub API calls from the build:
update:release-contributorsscript and the pre-generated data used byGitHubRepoStats. Commit it as JSON undersrc/frontend/src/data/, and refresh it on a schedule or by hand.astro-contributors'<ContributorList>with a component that renders from that JSON, and remove the dependency if nothing else uses it.api.github.comare caught.Setting
PUBLIC_GITHUB_TOKENis not the preferred fix. The build would still make network calls, and aPUBLIC_*variable can end up in the browser code if anything reads it on the client.