Skip to content

Commit 55b6e9d

Browse files
committed
fix: use GH_TOKEN env var for gh api PAT auth [skip-version]
- gh uses GITHUB_TOKEN by default, ignoring --header flag - Set GH_TOKEN env var so gh uses the PAT for all API calls - This enables cross-repo tag creation
1 parent f521512 commit 55b6e9d

1 file changed

Lines changed: 5 additions & 5 deletions

File tree

‎.github/workflows/build-and-publish.yml‎

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -139,6 +139,7 @@ jobs:
139139
env:
140140
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
141141
VERSION: ${{ steps.bump.outputs.version }}
142+
GH_TOKEN: ${{ secrets.LOCALPIBOX_PAT }}
142143
run: |
143144
set -e
144145
# repo -> default branch mapping
@@ -154,14 +155,13 @@ jobs:
154155
echo "Tagging $repo@$VERSION (from $branch)"
155156
sha=$(git ls-remote "https://github.com/$repo.git" "refs/heads/$branch" | awk '{print $1}')
156157
if [ -n "$sha" ]; then
157-
# Create lightweight tag using PAT (GITHUB_TOKEN is scoped to devstack only)
158+
# GH_TOKEN env var makes gh use PAT for all API calls
159+
# Create lightweight tag: POST to /git/refs/{ref} with sha body
158160
if gh api "repos/$repo/git/refs/refs/tags/$VERSION" \
159161
--method POST \
160-
-f sha="$sha" \
161-
--header "Authorization: token $LOCALPIBOX_PAT" \
162-
2>/dev/null; then
162+
-f sha="$sha"; then
163163
echo " ✅ $repo@$VERSION"
164-
elif gh api "repos/$repo/git/ref/tags/$VERSION" --header "Authorization: token $LOCALPIBOX_PAT" 2>/dev/null > /dev/null; then
164+
elif gh api "repos/$repo/git/ref/tags/$VERSION" 2>/dev/null > /dev/null; then
165165
echo " ✅ $repo@$VERSION (already exists)"
166166
else
167167
echo " ⚠️ $repo tag creation failed"

0 commit comments

Comments
 (0)