Skip to content

safe_outputs checkout sets persist-credentials: true and fails on git 2.55 (could not read Username) #64483

Description

@rameshreddy-adutla

The compiled safe_outputs job emits its "Checkout repository" step with
persist-credentials: true, unlike the agent/detection checkouts which use
persist-credentials: false. On a runner with git 2.55.0, only the
persist-credentials: true checkout fails at fetch:

fatal: could not read Username for 'https://github.com': terminal prompts disabled
(exit code 128)

Every persist-credentials: false checkout in the same run succeeds on the same
runner, and the token is valid (the same token is used successfully by
github-script steps in other jobs of the run). actions/checkout is on the latest
release (v7.0.1), so this is not an out-of-date action.

The safe_outputs job already runs its own git credential configuration step
(configure_git_credentials.sh) immediately after checkout, so the push does not
rely on the checkout persisting credentials. persist-credentials: true buys
nothing here and is the trigger for the failure.

Request: emit persist-credentials: false for the safe_outputs checkout
(aligning it with the agent/detection checkouts), or make it configurable.

Environment: self-hosted Linux runner, git 2.55.0, actions/checkout@v7.0.1.

Activity

  1. locked and limited conversation to collaborators on Sep 30, 2026
  2. unlocked this conversation on Sep 30, 2026
  3. pelikhan commented on Sep 30, 2026

    @pelikhan
    Collaborator

    @copilot all git write operations should be done in other jobs

  4. rameshreddy-adutla commented on Oct 1, 2026

    @rameshreddy-adutla
    Author

    @pelikhan, I saw your note that git writes should happen in other jobs, and that #64496 was closed without merging. For the create_pull_request and push_to_pull_request_branch paths, should the checkout move out of safe_outputs entirely, rather than just switch to persist-credentials: false? We’re carrying a temporary control-plane patch for the checkout failure, so I’d like to align it with the intended upstream design. What’s the preferred change?

  5. pelikhan commented on Oct 1, 2026

    @pelikhan
    Collaborator

    @rameshreddy-adutla i need to spend more time reviewing this one.

  6. locked and limited conversation to collaborators on Oct 1, 2026
  7. unlocked this conversation on Oct 1, 2026
  8. pelikhan commented on Oct 7, 2026

    @pelikhan
    Collaborator

    Status (2026-10-07; Maintainer direction): The September 30 maintainer comment says git writes should happen in other jobs, but the maintainer said on October 1 that this issue needs more review; #64496 closed without merging. The next step is to confirm whether the safe-outputs checkout should move to another job or retain its current placement with persist-credentials: false.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions