Correct comment about where checkout persists the PAT

Current actions/checkout stores the token in $RUNNER_TEMP and wires a
git credential helper, rather than writing the token into .git/config's
http.extraheader. The mechanism that makes `git push` pick up the PAT
is unchanged at the caller's level; the comment was just wrong about
where the secret lives on disk.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
Ullrich Schäfer 2026-04-19 20:56:54 +02:00
parent 32ea0f66f5
commit 5d9ffae38a
No known key found for this signature in database
GPG key ID: A32FF691A0F752D9

View file

@ -42,11 +42,13 @@ jobs:
- uses: actions/checkout@v6
with:
ref: ${{ github.head_ref }}
# Persist this token in .git/config's http.extraheader so the
# later `git push` authenticates as the PAT. That's what makes
# the dedupe commit trigger CI. `persist-credentials: true` is
# the checkout default — made explicit here so the mechanism
# is visible from the YAML instead of implicit in the action.
# With `persist-credentials: true`, checkout stores this token
# in $RUNNER_TEMP and wires a git credential helper that
# supplies it on subsequent HTTPS git calls. That's what makes
# the later `git push` authenticate as the PAT, which in turn
# re-triggers CI on the dedupe commit. `true` is the checkout
# default — made explicit here so the mechanism is visible
# from the YAML instead of implicit in the action.
token: ${{ secrets.DEPENDABOT_DEDUPE_TOKEN }}
persist-credentials: true
- uses: pnpm/action-setup@v6