Skip to content

ADFA-4918 fix(ci): pass GITHUB_TOKEN to release & Firebase builds - #279

Merged
luisguzman-adfa merged 3 commits into
mainfrom
fix/ADFA-4918-ci-release-firebase-token
Jul 29, 2026
Merged

luisguzman-adfa merged 3 commits into
mainfrom
fix/ADFA-4918-ci-release-firebase-token

Conversation

@luisguzman-adfa

Copy link
Copy Markdown
Collaborator

Both the release and Firebase workflows run assembleRelease -> :app:syncNativeArtifacts, which queries the GitHub API for the pinned binaries release and 403s unauthenticated on shared CI runners. Pass GITHUB_TOKEN so the M15 fallback in build.gradle can retry authenticated (as android-sanity-check.yml already does). Same repo, so the auto token's contents:read is enough.

Both workflows run ./gradlew assembleRelease -> :app:syncNativeArtifacts, which
queries the GitHub API for the pinned binaries release. Unauthenticated it gets
HTTP 403 (shared-runner rate limit); the M15 fallback (build.gradle) retries with
GITHUB_TOKEN/GH_TOKEN from the env, but neither workflow passed a token, so the
retry had nothing and the build failed.

Add GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} to the build step env in
android-release-build.yml and firebase-distribution.yml (as android-sanity-check.yml
already does). Same repo, so the auto token's contents:read is enough.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant