Skip to content

fix: extra-empty-commit trigger push authenticates as CI-trigger token, not GITHUB_TOKEN - #44169

Closed
pelikhan with Copilot wants to merge 1 commit into
mainfrom
copilot/fix-empty-commit-ci-trigger
Closed

pelikhan with Copilot wants to merge 1 commit into
mainfrom
copilot/fix-empty-commit-ci-trigger

Conversation

Copilot AI commented Jul 8, 2026 •

Copy link
Copy Markdown
Contributor

GH_AW_CI_TRIGGER_TOKEN / github-token-for-extra-empty-commit was silently ignored. The actions/checkout persist-credentials: true default writes http.<serverUrl>/.extraheader carrying GITHUB_TOKEN; git applies that header to every matching request, taking precedence over any token embedded in the remote URL. The empty commit was pushed as github-actions[bot], so no CI runs were triggered.

Changes

  • actions/setup/js/git_auth_helpers.cjs (new): shared helpers for http.<serverUrl>/.extraheader management — getPersistedExtraheader, checkoutHasPersistedExtraheader (moved from dynamic_checkout.cjs), overridePersistedExtraheader (--replace-all to collapse to a single Authorization header), restorePersistedExtraheader

  • actions/setup/js/extra_empty_commit.cjs: before the push, override the extraheader with the CI-trigger token; use a credential-free remote URL; restore the original extraheader in a finally block so the token doesn't leak into subsequent steps:

    prevExtraheader = await getPersistedExtraheader(githubServerUrl);
    await overridePersistedExtraheader(githubServerUrl, token); // git config --replace-all
    // ... credential-free remote URL, fetch, commit, push ...
    // finally: restorePersistedExtraheader(githubServerUrl, prevExtraheader)
  • actions/setup/js/dynamic_checkout.cjs: import checkoutHasPersistedExtraheader from the shared module

  • actions/setup/js/extra_empty_commit.test.cjs / extra_empty_commit.integration.test.cjs: add getExecOutput mock, new tests asserting the --replace-all override fires before push with correct base64 token, and the extraheader is restored/unset after push

  • docs/src/content/docs/reference/triggering-ci.mdx: clarify the trigger works regardless of persist-credentials state; add troubleshooting note (verify actor is the PAT/App identity, not github-actions[bot])

Copilot AI changed the title [WIP] Fix extra empty commit not triggering CI fix: extra-empty-commit trigger push authenticates as CI-trigger token, not GITHUB_TOKEN Jul 8, 2026
Copilot AI requested a review from pelikhan July 8, 2026 03:29
@pelikhan pelikhan closed this Jul 8, 2026
@github-actions
github-actions Bot deleted the copilot/fix-empty-commit-ci-trigger branch July 16, 2026 02:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

2 participants