-
Notifications
You must be signed in to change notification settings - Fork 7
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Private repos require you to set process.env.GH_ADMIN_TOKEN to fetch the latest SHA #73
Comments
Hey @lucasgonze! Thanks for the report. I've just run a test locally with Could you clone the repo, uncomment lines 41 and 55 in (As an aside, I need to add an easier way to get debug logs) |
Done. sample.txt shows a complete log of one failed request matching the above pattern. I think the key is this bit:
|
Yep! That'd do it. I'll add some additional handling that makes it clearer what's going on when you get rate limited. In this case, you'll need to configure the GitHub token to increase your rate limit |
That makes total sense. I agree that a better error message would get the job done. |
v1.6.0 just went out with a fix for the error message and better logging. Thanks for the report |
🙏 LGTM |
Done with pin-github-action <https://github.com/mheap/pin-github-action> 1.8.0 using `npx pin-github-action .github/workflows/*.yml`. Dependabot should support updating in the same fashion <dependabot/dependabot-core#8277 (comment)>. Had to `export GH_ADMIN_TOKEN=github_pat_…` using a fine-grained personal access tokens with no extra access to work around rate limiting *and* to be able to work in private repos <mheap/pin-github-action#73>.
Done with pin-github-action <https://github.com/mheap/pin-github-action> 1.8.0 using `npx pin-github-action .github/workflows/*.yml`. Dependabot should support updating in the same fashion <dependabot/dependabot-core#8277 (comment)>. Had to `export GH_ADMIN_TOKEN=github_pat_…` using a fine-grained personal access tokens with no extra access to work around rate limiting *and* to be able to work in private repos <mheap/pin-github-action#73>.
Done with pin-github-action <https://github.com/mheap/pin-github-action> 1.8.0 using `npx pin-github-action .github/workflows/*.yml`. Dependabot should support updating in the same fashion <dependabot/dependabot-core#8277 (comment)>. Had to `export GH_ADMIN_TOKEN=github_pat_…` using a fine-grained personal access tokens with no extra access to work around rate limiting *and* to be able to work in private repos <mheap/pin-github-action#73>.
Done with pin-github-action <https://github.com/mheap/pin-github-action> 1.8.0 using `npx pin-github-action .github/workflows/*.yml`. Dependabot should support updating in the same fashion <dependabot/dependabot-core#8277 (comment)>. Had to `export GH_ADMIN_TOKEN=github_pat_…` using a fine-grained personal access tokens with no extra access to work around rate limiting *and* to be able to work in private repos <mheap/pin-github-action#73>.
Done with pin-github-action <https://github.com/mheap/pin-github-action> 1.8.0 using `npx pin-github-action .github/workflows/*.yml`. Dependabot should support updating in the same fashion <dependabot/dependabot-core#8277 (comment)>. Had to `export GH_ADMIN_TOKEN=github_pat_…` using a fine-grained personal access tokens with no extra access to work around rate limiting *and* to be able to work in private repos <mheap/pin-github-action#73>.
Done with pin-github-action <https://github.com/mheap/pin-github-action> 1.8.0 using `npx pin-github-action .github/workflows/*.yml`. Dependabot should support updating in the same fashion <dependabot/dependabot-core#8277 (comment)>. Had to `export GH_ADMIN_TOKEN=github_pat_…` using a fine-grained personal access tokens with no extra access to work around rate limiting *and* to be able to work in private repos <mheap/pin-github-action#73>.
Done with pin-github-action <https://github.com/mheap/pin-github-action> 1.8.0 using `npx pin-github-action .github/workflows/*.yml`. Dependabot should support updating in the same fashion <dependabot/dependabot-core#8277 (comment)>. Had to `export GH_ADMIN_TOKEN=github_pat_…` using a fine-grained personal access tokens with no extra access to work around rate limiting *and* to be able to work in private repos <mheap/pin-github-action#73>.
Done with pin-github-action <https://github.com/mheap/pin-github-action> 1.8.0 using `npx pin-github-action .github/workflows/*.yml`. Dependabot should support updating in the same fashion <dependabot/dependabot-core#8277 (comment)>. Had to `export GH_ADMIN_TOKEN=github_pat_…` using a fine-grained personal access tokens with no extra access to work around rate limiting *and* to be able to work in private repos <mheap/pin-github-action#73>.
Done with pin-github-action <https://github.com/mheap/pin-github-action> 1.8.0 using `npx pin-github-action .github/workflows/*.yml`. Dependabot should support updating in the same fashion <dependabot/dependabot-core#8277 (comment)>. Had to `export GH_ADMIN_TOKEN=github_pat_…` using a fine-grained personal access tokens with no extra access to work around rate limiting *and* to be able to work in private repos <mheap/pin-github-action#73>.
Done with pin-github-action <https://github.com/mheap/pin-github-action> 1.8.0 using `npx pin-github-action .github/workflows/*.y*ml`. Dependabot should support updating in the same fashion <dependabot/dependabot-core#8277 (comment)>. Had to `export GH_ADMIN_TOKEN=github_pat_…` using a fine-grained personal access tokens with no extra access to work around rate limiting *and* to be able to work in private repos <mheap/pin-github-action#73>.
Done with pin-github-action <https://github.com/mheap/pin-github-action> 1.8.0 using `npx pin-github-action .github/workflows/*.y*ml`. Dependabot should support updating in the same fashion <dependabot/dependabot-core#8277 (comment)>. Had to `export GH_ADMIN_TOKEN=github_pat_…` using a fine-grained personal access tokens with no extra access to work around rate limiting *and* to be able to work in private repos <mheap/pin-github-action#73>.
Done with pin-github-action <https://github.com/mheap/pin-github-action> 1.8.0 using `npx pin-github-action .github/workflows/*.yml`. Dependabot should support updating in the same fashion <dependabot/dependabot-core#8277 (comment)>. Had to `export GH_ADMIN_TOKEN=github_pat_…` using a fine-grained personal access tokens with no extra access to work around rate limiting *and* to be able to work in private repos <mheap/pin-github-action#73>.
Done with pin-github-action <https://github.com/mheap/pin-github-action> 1.8.0 using `npx pin-github-action .github/workflows/*.y*ml`. Dependabot should support updating in the same fashion <dependabot/dependabot-core#8277 (comment)>. Had to `export GH_ADMIN_TOKEN=github_pat_…` using a fine-grained personal access tokens with no extra access to work around rate limiting *and* to be able to work in private repos <mheap/pin-github-action#73>. # Conflicts: # .github/workflows/codeql-analysis.yml
Done with pin-github-action <https://github.com/mheap/pin-github-action> 1.8.0 using `npx pin-github-action .github/workflows/*.yml`. Dependabot should support updating in the same fashion <dependabot/dependabot-core#8277 (comment)>. Had to `export GH_ADMIN_TOKEN=github_pat_…` using a fine-grained personal access tokens with no extra access to work around rate limiting *and* to be able to work in private repos <mheap/pin-github-action#73>.
Done with pin-github-action <https://github.com/mheap/pin-github-action> 1.8.0 using `npx pin-github-action .github/workflows/*.yml`. Dependabot should support updating in the same fashion <dependabot/dependabot-core#8277 (comment)>. Had to `export GH_ADMIN_TOKEN=github_pat_…` using a fine-grained personal access tokens with no extra access to work around rate limiting *and* to be able to work in private repos <mheap/pin-github-action#73>.
Done with pin-github-action <https://github.com/mheap/pin-github-action> 1.8.0 using `npx pin-github-action --comment=' {ref}' .github/workflows/*.y*ml`. Dependabot should support updating in the same fashion <dependabot/dependabot-core#8277 (comment)>. Had to `export GH_ADMIN_TOKEN=github_pat_…` using a fine-grained personal access tokens with no extra access to work around rate limiting *and* to be able to work in private repos <mheap/pin-github-action#73>.
Done with pin-github-action <https://github.com/mheap/pin-github-action> 1.8.0 using `npx pin-github-action .github/workflows/*.yml`. Dependabot should support updating in the same fashion <dependabot/dependabot-core#8277 (comment)>. Had to `export GH_ADMIN_TOKEN=github_pat_…` using a fine-grained personal access tokens with no extra access to work around rate limiting *and* to be able to work in private repos <mheap/pin-github-action#73>.
Done with pin-github-action <https://github.com/mheap/pin-github-action> 1.8.0 using `npx pin-github-action --comment=' {ref}' .github/workflows/*.y*ml`. Dependabot should support updating in the same fashion <dependabot/dependabot-core#8277 (comment)>. Had to `export GH_ADMIN_TOKEN=github_pat_…` using a fine-grained personal access tokens with no extra access to work around rate limiting *and* to be able to work in private repos <mheap/pin-github-action#73>.
Done with pin-github-action <https://github.com/mheap/pin-github-action> 1.8.0 using `npx pin-github-action .github/workflows/*.yml`. Dependabot should support updating in the same fashion <dependabot/dependabot-core#8277 (comment)>. Had to `export GH_ADMIN_TOKEN=github_pat_…` using a fine-grained personal access tokens with no extra access to work around rate limiting *and* to be able to work in private repos <mheap/pin-github-action#73>.
Done with pin-github-action <https://github.com/mheap/pin-github-action> 1.8.0 using `npx pin-github-action .github/workflows/*.yml`. Dependabot should support updating in the same fashion <dependabot/dependabot-core#8277 (comment)>. Had to `export GH_ADMIN_TOKEN=github_pat_…` using a fine-grained personal access tokens with no extra access to work around rate limiting *and* to be able to work in private repos <mheap/pin-github-action#73>.
Hellos @mheap. Thanks for this excellent tool.
I am running it against build files in a public repo and getting an unexpected error:
These are the specific actions triggering the issue:
My understanding is that these are not private repos and shouldn't require a token.
uses: actions/checkout@main
is an example in your own home page.I can work around the issue for now, but it does complicate my team's usage of the tool so it's worth asking about.
The text was updated successfully, but these errors were encountered: