Skip to content

ci: authenticate go-git tag push in publish workflow - #75

Merged
sonnes merged 1 commit into
mainfrom
fix/publish-tag-auth
Jul 2, 2026
Merged

sonnes merged 1 commit into
mainfrom
fix/publish-tag-auth

Conversation

@sonnes

@sonnes sonnes commented Jul 2, 2026

Copy link
Copy Markdown
Collaborator

Problem

The Publish workflow failed on the last release (run):

INF Pushing tags to origin
Failed to push tags: pushing tags: authentication required: No anonymous write access.

All tags were created but none were pushed — xkafka/v0.11.1 (and the cascade dependency tags) had to be pushed manually to complete the release.

Root cause

changeset publish pushes via go-git — PushTags calls repo.Push(&git.PushOptions{...}) with no Auth. go-git does not read the http.<url>.extraheader credential that actions/checkout injects for the GITHUB_TOKEN, so the push goes out anonymously and GitHub rejects it.

Fix (workflow-only)

  • permissions: contents: write on the job so the token has push scope.
  • Rewrite the origin remote URL to embed the token (https://x-access-token:${GITHUB_TOKEN}@github.com/...). go-git does read URL userinfo, so the push now authenticates.

No change to the changeset tool or its released version.

Follow-up (optional, deeper fix)

The tool itself should authenticate its own push so it works in any CI without URL hacks: add Auth: &http.BasicAuth{Username: "x-access-token", Password: os.Getenv("GITHUB_TOKEN")} to PushTags in cmd/changeset/git/git.go. Left out here to keep this change to the workflow and avoid re-releasing cmd/changeset.

Notes

  • CI-only change → empty changeset included (per the repo's documented convention for CI/docs PRs); no module is released.

changeset publish pushes tags via go-git, which ignores the http.extraheader
credentials actions/checkout configures. The push therefore went out
anonymously and failed with "authentication required: No anonymous write
access", so no tags were published (xkafka/v0.11.1 had to be tagged manually).

Embed the GITHUB_TOKEN in the origin URL (which go-git does read) and grant
the job contents: write so the token can push tags.
@codecov-commenter

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 60.32%. Comparing base (fbbbee2) to head (b213dbd).

Additional details and impacted files
@@            Coverage Diff             @@
##             main      #75      +/-   ##
==========================================
- Coverage   60.37%   60.32%   -0.06%     
==========================================
  Files          80       80              
  Lines        3599     3599              
==========================================
- Hits         2173     2171       -2     
- Misses       1396     1398       +2     
  Partials       30       30              

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@sonnes
sonnes merged commit a90b3aa into main Jul 2, 2026
3 checks passed
@sonnes
sonnes deleted the fix/publish-tag-auth branch July 2, 2026 09:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants