Skip to content

Disable credential persistence for safe-output checkouts - #64496

Closed
pelikhan with Copilot wants to merge 2 commits into
mainfrom
copilot/fix-persist-credentials-issue
Closed

pelikhan with Copilot wants to merge 2 commits into
mainfrom
copilot/fix-persist-credentials-issue

Conversation

Copilot AI commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Safe-output checkouts persisted credentials unnecessarily, causing authentication failures with Git 2.55. Subsequent fetch and push operations already use the dedicated Git credential configuration step.

  • Checkout generation

    • Emit persist-credentials: false for safe-output PR checkouts.
    • Stop injecting the push token into actions/checkout.
    • Continue configuring fetch/push credentials after checkout.
  • Regression coverage

    • Require credential-free checkouts for create-PR and push-to-PR-branch outputs.
    • Verify the safe-output token still reaches the Git credential configuration step.
- name: Checkout repository
  uses: actions/checkout@v7
  with:
    persist-credentials: false

- name: Configure Git credentials
  run: bash "${RUNNER_TEMP}/gh-aw/actions/configure_git_credentials.sh"

Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Copilot AI changed the title [WIP] Fix safe_outputs checkout for persist-credentials failure Disable credential persistence for safe-output checkouts Sep 30, 2026
Copilot AI requested a review from pelikhan September 30, 2026 13:12
@pelikhan pelikhan closed this Sep 30, 2026
@github-actions
github-actions Bot deleted the copilot/fix-persist-credentials-issue branch October 8, 2026 02:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

safe_outputs checkout sets persist-credentials: true and fails on git 2.55 (could not read Username)

2 participants