Skip to content

ci: persist-credentials:false for private-dep auth - #3

Merged
TheCryptoDonkey merged 1 commit into
mainfrom
ci/persist-credentials-false
Jul 18, 2026
Merged

TheCryptoDonkey merged 1 commit into
mainfrom
ci/persist-credentials-false

Conversation

@TheCryptoDonkey

Copy link
Copy Markdown
Member

The CI job injects FORGESWORN_READ_PAT via git insteadOf to fetch a private @forgesworn dependency, but the checkout step persisted the workflow GITHUB_TOKEN as an http extraheader which overrides that rewrite (GITHUB_TOKEN cannot read other repos → npm ci 404). Set persist-credentials: false on checkout so the PAT rewrite wins.

Additive workflow-only change; no code, no version, no tag. Hosted checks still require the FORGESWORN_READ_PAT secret to be provisioned in this repo before they can fully pass.

🤖 Generated with Claude Code

@TheCryptoDonkey
TheCryptoDonkey merged commit 55bd3e8 into main Jul 18, 2026
0 of 2 checks passed
@TheCryptoDonkey
TheCryptoDonkey deleted the ci/persist-credentials-false branch July 18, 2026 21:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant