Fix the same release-token bug in the Android release workflow - #58
Merged
Merged
Conversation
build-release.yml had the identical wiring the exporter workflow did: the PAT
passed to softprops/action-gh-release@v2 as a GITHUB_TOKEN environment
variable. The action's `token` input defaults to ${{ github.token }}, and its
docs say "a non-empty explicit token overrides GITHUB_TOKEN" - so the default is
always non-empty and the env var is ignored. It authenticates as the built-in
token, which is read-only here, and fails with 403 after the APK has been built
and signed.
#54 fixed this for the exporter because that was the release being cut. This
workflow was never re-run, so it has been sitting on the same fault - and the
next Android release would have failed at the last step, after the signing, in
exactly the same way.
Token moved into `with:`, and contents: write granted to the job so an unset or
expired PAT degrades to a working upload rather than a 403.
Checked the other workflows: update-contributors.yml also sets GITHUB_TOKEN as
an environment variable, but that one is the built-in token being handed to
scripts/fetch_contributors.py, which reads it from the environment. Not the same
thing, and correct as written.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
build-release.ymlhas the identical wiring that broke the exporter release:softprops/action-gh-release@v2takes its credential as thetokeninput, which defaults to${{ github.token }}. Its own docs: "a non-empty explicit token overrides GITHUB_TOKEN" — the default is always non-empty, so an env var is ignored outright. The action then authenticates as the built-in token, which is read-only in this repository, and fails with 403Resource not accessible by integration.#54 fixed this for the macOS exporter, because that was the release being cut at the time. This workflow was never re-run, so it has been sitting on the same fault — and the next Android release would have failed at the very last step, after building and signing the APK.
Found while checking what stood between here and an Android release, rather than by running it.
Fix
with:permissions: contents: writeon the job, so an unset or expired PAT degrades to a working upload rather than a 403Other workflows
update-contributors.ymlalso setsGITHUB_TOKENas an environment variable, but that is the built-in token being handed toscripts/fetch_contributors.py, which reads it from the environment. Different thing, correct as written. No other instances.Still asymmetric, deliberately not fixed here
The exporter release verifies its tag against
VERSIONin the source before either binary builds (scripts/exporter_version.py, gated intest-release-version). The Android release has no equivalent, so anandroid-app-v*tag can drift fromversionNamethe way the exporter's used to. Worth closing separately — this PR is only the thing that would break the next release outright.🤖 Generated with Claude Code