Skip to content

fix: authenticate GitHub update checks - #326

Draft
edouardb wants to merge 1 commit into
masterfrom
vibe/authenticated-update-check-ab3676
Draft

edouardb wants to merge 1 commit into
masterfrom
vibe/authenticated-update-check-ab3676

Conversation

@edouardb

Copy link
Copy Markdown
Member

Summary

  • authenticate automatic GitHub release checks with GH_TOKEN when available
  • continue supporting GITHUB_TOKEN, then fall back to gh auth token
  • preserve unauthenticated checks when no token source is available
  • add coverage for token precedence, GitHub CLI fallback, and fallback errors

Verification

  • git diff --check
  • targeted Go tests could not be run locally because Go is not installed and the Docker daemon is unavailable

Alternatives considered

  1. Implemented: use GH_TOKEN, then GITHUB_TOKEN, then gh auth token; this works automatically for existing GitHub CLI users while keeping CI-friendly environment variables.
  2. Only document/export GITHUB_TOKEN=$(gh auth token); smallest code change, but requires users to alter every shell/session and does not recognize GH_TOKEN directly.
  3. Remove or make the automatic release check opt-in; eliminates incidental GitHub API requests, but loses automatic update notifications for most users.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants