github-token validation fails with new GitHub stateless token format
Description
Since mid-May 2026, the action fails at startup with the following error:
"github-token" length must be less than or equal to 100 characters long
This is caused by the Joi validation in src/schema.js:
'github-token': Joi.string().trim().max(100),
Root cause
GitHub has begun a staged rollout of a new stateless token format for GitHub App installation tokens, which includes the GITHUB_TOKEN used in Actions workflows.
The new tokens are significantly longer (~520 characters) compared to the previous format, and thus exceed the hardcoded .max(100) limit enforced by Joi.
Relevant GitHub announcements:
Proposed fix
Remove or significantly raise the .max(100) constraint on github-token in src/schema.js. Since the token is treated as an opaque string (as recommended by GitHub), there is no practical reason to validate its length — tokens should simply be checked for presence:
// Before
'github-token': Joi.string().trim().max(100),
// After
'github-token': Joi.string().trim(),
Workaround
No reliable client-side workaround exists at this time, as the token length is controlled by GitHub's infrastructure and will progressively affect all repositories during the rollout period.
github-tokenvalidation fails with new GitHub stateless token formatDescription
Since mid-May 2026, the action fails at startup with the following error:
This is caused by the Joi validation in
src/schema.js:Root cause
GitHub has begun a staged rollout of a new stateless token format for GitHub App installation tokens, which includes the
GITHUB_TOKENused in Actions workflows.The new tokens are significantly longer (~520 characters) compared to the previous format, and thus exceed the hardcoded
.max(100)limit enforced by Joi.Relevant GitHub announcements:
ghs_APPID_JWTformat and its increased length (~520 chars)GITHUB_TOKEN(server-to-server tokens)Proposed fix
Remove or significantly raise the
.max(100)constraint ongithub-tokeninsrc/schema.js. Since the token is treated as an opaque string (as recommended by GitHub), there is no practical reason to validate its length — tokens should simply be checked for presence:Workaround
No reliable client-side workaround exists at this time, as the token length is controlled by GitHub's infrastructure and will progressively affect all repositories during the rollout period.