crickets-and-comb/shared

Don't use CHECKOUT_SHARED org token for actions/checkout.

Open

#32 opened on Mar 21, 2025

View on GitHub
 (0 comments) (0 reactions) (0 assignees)Makefile (0 forks)auto 404
enhancementhelp wanted

Repository metrics

Stars
 (2 stars)
PR merge metrics
 (PR metrics pending)

Description

In several workflows, where we use the GitHub action action/checkout to checkout the repository, we pass it an org secret called CHECKOUT_SHARED. Typically this accepts the temporary GITHUB_TOKEN, which is generated for each use and expires after use. This is preferred to passing a relatively permanent org secret to a third-party action.

Somehow, maybe because the checkout is recursive in order to checkout the shared git submodule, passing GITHUB_TOKEN has not worked correctly. (Details of repro unavailable at this time, so we'll need a fresh repro.)

There may yet be a way to just pass GITHUB_TOKEN. But, another solution would be to replace the action altogether with an in-house checkout. It may just be a simple shell git checkout. It can be wrapped in a reusable workflow if it's not a simple one-liner.

Replacing the action altogether would fulfill the adjacent goal to replace as many third-party actions as possible: https://github.com/crickets-and-comb/shared/issues/37

Contributor guide