From cd92ba4b4d72c899152c63ea50f4fd645d2cbf23 Mon Sep 17 00:00:00 2001 From: phall Date: Sun, 27 Sep 2026 14:26:45 -0400 Subject: [PATCH] ci(release): authenticate the tag push as basic auth The tag push sent RELEASE_PLEASE_TOKEN as an AUTHORIZATION: bearer header, which GitHub's git endpoint does not accept for PATs, so git fell back to prompting for a username and the 1.6.0 tag job failed. Push with the token as the basic-auth password instead. Co-Authored-By: Claude Opus 5.5 (1M context) --- .github/workflows/release-tag.yml | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/.github/workflows/release-tag.yml b/.github/workflows/release-tag.yml index e7f0ceb..f68fc51 100644 --- a/.github/workflows/release-tag.yml +++ b/.github/workflows/release-tag.yml @@ -52,8 +52,10 @@ jobs: exit 0 fi git tag -a "${tag}" -m "phig ${{ steps.version.outputs.version }} (tagged by release-tag on merge of the release PR)" - git -c http.https://github.com/.extraheader="AUTHORIZATION: bearer ${RELEASE_PLEASE_TOKEN}" \ - push "https://github.com/${GITHUB_REPOSITORY}.git" "refs/tags/${tag}" + # Git's HTTPS endpoint takes a PAT as basic-auth password, not as + # a bearer header; the token is masked in logs. + git push "https://x-access-token:${RELEASE_PLEASE_TOKEN}@github.com/${GITHUB_REPOSITORY}.git" \ + "refs/tags/${tag}" - name: Mark the release PR as tagged env: GH_TOKEN: ${{ github.token }}