Skip to content

Fix the same release-token bug in the Android release workflow - #58

Merged
parawanderer merged 1 commit into
mainfrom
fix/android-release-token
Aug 9, 2026
Merged

parawanderer merged 1 commit into
mainfrom
fix/android-release-token

Conversation

@parawanderer

Copy link
Copy Markdown
Owner

build-release.yml has the identical wiring that broke the exporter release:

        env:
          GITHUB_TOKEN: ${{ secrets.ANDROID_BUILD_RELEASE_GITHUB_TOKEN }}

softprops/action-gh-release@v2 takes its credential as the token input, which defaults to ${{ github.token }}. Its own docs: "a non-empty explicit token overrides GITHUB_TOKEN" — the default is always non-empty, so an env var is ignored outright. The action then authenticates as the built-in token, which is read-only in this repository, and fails with 403 Resource not accessible by integration.

#54 fixed this for the macOS exporter, because that was the release being cut at the time. This workflow was never re-run, so it has been sitting on the same fault — and the next Android release would have failed at the very last step, after building and signing the APK.

Found while checking what stood between here and an Android release, rather than by running it.

Fix

  • token moved into with:
  • permissions: contents: write on the job, so an unset or expired PAT degrades to a working upload rather than a 403

Other workflows

update-contributors.yml also sets GITHUB_TOKEN as an environment variable, but that is the built-in token being handed to scripts/fetch_contributors.py, which reads it from the environment. Different thing, correct as written. No other instances.

Still asymmetric, deliberately not fixed here

The exporter release verifies its tag against VERSION in the source before either binary builds (scripts/exporter_version.py, gated in test-release-version). The Android release has no equivalent, so an android-app-v* tag can drift from versionName the way the exporter's used to. Worth closing separately — this PR is only the thing that would break the next release outright.

🤖 Generated with Claude Code

build-release.yml had the identical wiring the exporter workflow did: the PAT
passed to softprops/action-gh-release@v2 as a GITHUB_TOKEN environment
variable. The action's `token` input defaults to ${{ github.token }}, and its
docs say "a non-empty explicit token overrides GITHUB_TOKEN" - so the default is
always non-empty and the env var is ignored. It authenticates as the built-in
token, which is read-only here, and fails with 403 after the APK has been built
and signed.

#54 fixed this for the exporter because that was the release being cut. This
workflow was never re-run, so it has been sitting on the same fault - and the
next Android release would have failed at the last step, after the signing, in
exactly the same way.

Token moved into `with:`, and contents: write granted to the job so an unset or
expired PAT degrades to a working upload rather than a 403.

Checked the other workflows: update-contributors.yml also sets GITHUB_TOKEN as
an environment variable, but that one is the built-in token being handed to
scripts/fetch_contributors.py, which reads it from the environment. Not the same
thing, and correct as written.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant