Skip to content

fix(action): Resolve any branch in a private repository - #29

Merged
aywrite merged 1 commit into
mainfrom
claude/stoic-ramanujan-xqxekr
Sep 30, 2026
Merged

aywrite merged 1 commit into
mainfrom
claude/stoic-ramanujan-xqxekr

Conversation

@aywrite

@aywrite aywrite commented Sep 30, 2026

Copy link
Copy Markdown
Owner

What changed

The workflows check out with persist-credentials: false, so a later git fetch has no credentials. A public repository answers the fetch anyway. A private one refuses it.

bin/resolve_ref.sh fetched any branch other than the one checked out, by name. So in a private repository, naming another branch as the candidate or baseline failed with could not read Username for 'https://github.com'.

A full checkout already has every branch as origin/<name>. The script now looks there before it fetches.

In a private repository these still need a fetch, and still fail:

  • a pull request number (its head is under refs/pull/, which a checkout does not fetch)
  • a commit that is on no branch or tag

Fixing those means handing the token to that one fetch. It would have to stay out of the step that runs the caller's build. That changes how the workflows handle credentials, so it is not part of this PR.

Docs:

  • actions/resolve-ref/README.md has a section saying which refs resolve in a private repository.
  • The quickstart's requirements tell a private repository to use tags, commits and the branch it runs from for now. That also holds for v0.6.0, which the quickstart pins and which lacks this fix.

How it was checked

  • I cloned the repository with the refspecs a full checkout uses and pointed origin at a private repository's URL.
    • Before the change, another branch failed with could not read Username. After it, the branch resolves.
    • A pull request number still fails the same way.
    • A tag and the checked-out branch resolve either way.
  • New tests in tests/test_resolve.py do the same against an origin that cannot be reached:
    • a branch that is not checked out resolves
    • a tag and a commit still resolve
    • a pull request number and an unknown branch still fail
  • The branch test fails without the change.
  • python3 -m pytest tests passes (424 tests), and pre-commit run --all-files is clean.

The workflows call this script through the pinned resolve-ref action. So callers get the fix with the next release, and no workflow change is needed.

🤖 Generated with Claude Code

https://claude.ai/code/session_018ccJFsmZ4jAKYmFNgNBh9u


Generated by Claude Code

The workflows check out with persist-credentials: false, so a later git
fetch has no credentials. A public repository answers it anyway and a
private one refuses it. resolve_ref.sh fetched any branch other than the
one checked out by name, so in a private repository that branch could
not be resolved.

A full checkout already has every branch as origin/<name>, so the
script now looks there before fetching. A pull request number and a
commit on no branch or tag still need a fetch, and still fail in a
private repository. The resolve-ref README says which refs work there,
and the quickstart says to keep to those for now.

Checked by pointing a clone with the checkout's refspecs at a private
repository's URL. Before this, another branch failed with "could not
read Username". Now it resolves, and a pull request number still fails
the same way. The new tests do the same against an origin that cannot
be reached.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018ccJFsmZ4jAKYmFNgNBh9u
@aywrite
aywrite merged commit 8102e5e into main Sep 30, 2026
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants