From 9bb402b3bf8d4c704a447ffd26a59e4b20544b19 Mon Sep 17 00:00:00 2001 From: maziggy Date: Mon, 29 Jun 2026 13:21:03 +0200 Subject: [PATCH] ci(repo-stats): use jgehrcke's PAT for gh-pages checkout MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The default GITHUB_TOKEN failed at `git fetch` for the gh-pages checkout step with opaque "exit code 1" and no surfaced git stderr, even with permissions: contents: write set at workflow level. actions/checkout's retry loop didn't recover. Switching the gh-pages checkout to secrets.GHRS_GITHUB_API_TOKEN — the same PAT jgehrcke/github-repo-stats already writes the branch with one step earlier — keeps the auth chain uniform and avoids the mismatch. persist-credentials defaults to true, so the subsequent commit-and-push step in the same gh-pages directory picks up the PAT automatically; no separate change to the push step needed. fetch-depth: 1 left explicit because checkout@v4 defaults to it but the value's load-bearing for this workflow (we only need HEAD of gh-pages, not history). --- .github/workflows/repo-stats.yml | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/.github/workflows/repo-stats.yml b/.github/workflows/repo-stats.yml index c64da1193..e7ae33159 100644 --- a/.github/workflows/repo-stats.yml +++ b/.github/workflows/repo-stats.yml @@ -34,6 +34,12 @@ jobs: with: ref: gh-pages path: gh-pages + # Same PAT jgehrcke writes gh-pages with — keeps the auth + # chain uniform and avoids the default GITHUB_TOKEN being + # rejected on fetch (root cause of the earlier "exit code 1" + # with no surfaced git stderr). + token: ${{ secrets.GHRS_GITHUB_API_TOKEN }} + fetch-depth: 1 - name: inject-ghcr-pulls run: |