Stop over-claiming the persist-credentials mechanism
The previous comment claimed `git push` reads the token via a git credential helper wired into $RUNNER_TEMP. I don't actually know that's how it works end to end — only that checkout stashes the token there and that subsequent git ops in the same workspace end up authenticating as the PAT. Describe just the observable contract, not an unverified internal path. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
parent
5d9ffae38a
commit
da56eb2c19
1 changed files with 7 additions and 7 deletions
14
.github/workflows/dependabot-dedupe.yml
vendored
14
.github/workflows/dependabot-dedupe.yml
vendored
|
|
@ -42,13 +42,13 @@ jobs:
|
|||
- uses: actions/checkout@v6
|
||||
with:
|
||||
ref: ${{ github.head_ref }}
|
||||
# With `persist-credentials: true`, checkout stores this token
|
||||
# in $RUNNER_TEMP and wires a git credential helper that
|
||||
# supplies it on subsequent HTTPS git calls. That's what makes
|
||||
# the later `git push` authenticate as the PAT, which in turn
|
||||
# re-triggers CI on the dedupe commit. `true` is the checkout
|
||||
# default — made explicit here so the mechanism is visible
|
||||
# from the YAML instead of implicit in the action.
|
||||
# With `persist-credentials: true`, this PAT is stashed by the
|
||||
# action (under $RUNNER_TEMP in recent versions) and made
|
||||
# available to subsequent git operations in this workspace —
|
||||
# so the later `git push` authenticates as the PAT, which is
|
||||
# what gets CI to re-trigger on the dedupe commit. `true` is
|
||||
# the checkout default; pinned explicitly here because it's
|
||||
# load-bearing for this workflow.
|
||||
token: ${{ secrets.DEPENDABOT_DEDUPE_TOKEN }}
|
||||
persist-credentials: true
|
||||
- uses: pnpm/action-setup@v6
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue