The compiled safe_outputs job emits its "Checkout repository" step with
persist-credentials: true, unlike the agent/detection checkouts which use
persist-credentials: false. On a runner with git 2.55.0, only the
persist-credentials: true checkout fails at fetch:
fatal: could not read Username for 'https://github.com': terminal prompts disabled
(exit code 128)
Every persist-credentials: false checkout in the same run succeeds on the same
runner, and the token is valid (the same token is used successfully by
github-script steps in other jobs of the run). actions/checkout is on the latest
release (v7.0.1), so this is not an out-of-date action.
The safe_outputs job already runs its own git credential configuration step
(configure_git_credentials.sh) immediately after checkout, so the push does not
rely on the checkout persisting credentials. persist-credentials: true buys
nothing here and is the trigger for the failure.
Request: emit persist-credentials: false for the safe_outputs checkout
(aligning it with the agent/detection checkouts), or make it configurable.
Environment: self-hosted Linux runner, git 2.55.0, actions/checkout@v7.0.1.
The compiled safe_outputs job emits its "Checkout repository" step with
persist-credentials: true, unlike the agent/detection checkouts which use
persist-credentials: false. On a runner with git 2.55.0, only the
persist-credentials: true checkout fails at fetch:
Every persist-credentials: false checkout in the same run succeeds on the same
runner, and the token is valid (the same token is used successfully by
github-script steps in other jobs of the run). actions/checkout is on the latest
release (v7.0.1), so this is not an out-of-date action.
The safe_outputs job already runs its own git credential configuration step
(configure_git_credentials.sh) immediately after checkout, so the push does not
rely on the checkout persisting credentials. persist-credentials: true buys
nothing here and is the trigger for the failure.
Request: emit persist-credentials: false for the safe_outputs checkout
(aligning it with the agent/detection checkouts), or make it configurable.
Environment: self-hosted Linux runner, git 2.55.0, actions/checkout@v7.0.1.