GitHub API requests ignore proxy environment variables on GitHub Enterprise Server
Dieses Issue hat noch niemand übernommen.
Bewertung
- Schwierigkeit
- 4/5
- Geschätzter Aufwand
- 3-5 Tage
- Anfängerfreundlichkeit
- 68/100
- Issue-Typ
- Bug
- Klarheit
- Größtenteils klar
- Aktivitätsstatus
- Aktiv
- Tech-Stack
- github-actions, node.js, typescript
Rechercherichtung
Start in src/client/github/client.ts and compare its Octokit setup with the proxy-aware configuration in @actions/github and the linked Octokit and Node.js documentation. Verify the chosen request.fetch or dispatcher approach handles the documented proxy variables, CONNECT requests, and proxy authentication where supported; done means GitHub API calls use the proxy and the reported self-hosted-runner scenario no longer times out.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Beschreibung
Description
ctrf-io/github-test-reporter cannot post or update comments when the GitHub Enterprise Server API is accessible from the runner only through an HTTP forward proxy.
The proxy environment variables are configured, but the reporter appears to connect directly to the GitHub Enterprise Server host instead of using the proxy. Because direct access is blocked by the firewall, the connection times out.
This affects features that use the GitHub API, including pull request comments, issue comments, historical reports, and artifact retrieval.
Environment
- Action:
ctrf-io/github-test-reporter@v1 - GitHub platform: GitHub Enterprise Server
- Runner: self-hosted
- Action runtime: Node.js 24
- Target API:
https://github.example.com/api/v3 - Network: GitHub Enterprise Server is reachable from the runner only through an HTTP forward proxy
All company-specific hostnames, repository names, and proxy addresses in this report have been replaced with placeholders.
Proxy configuration
The standard proxy environment variables are configured for the action:
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
HTTP_PROXY: http://proxy.example.com:8080
HTTPS_PROXY: http://proxy.example.com:8080
http_proxy: http://proxy.example.com:8080
https_proxy: http://proxy.example.com:8080
A proxy-aware client such as curl can reach the same GitHub Enterprise API endpoint from the runner when configured to use this proxy.
Steps to reproduce
Run the reporter on a self-hosted runner where direct access to GitHub Enterprise Server is blocked, but access through an HTTP forward proxy is available:
- name: Publish test report
uses: ctrf-io/github-test-reporter@v1
if: always()
with:
report-path: path/to/ctrf-report.json
pull-request-report: true
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
HTTP_PROXY: http://proxy.example.com:8080
HTTPS_PROXY: http://proxy.example.com:8080
http_proxy: http://proxy.example.com:8080
https_proxy: http://proxy.example.com:8080
Actual behavior
The request is retried three times and then fails with a connection timeout:
GET /repos/example-org/example-repo/issues/143/comments?per_page=100 - 500 with id UNKNOWN in 10598ms
GET /repos/example-org/example-repo/issues/143/comments?per_page=100 - 500 with id UNKNOWN in 10510ms
GET /repos/example-org/example-repo/issues/143/comments?per_page=100 - 500 with id UNKNOWN in 10545ms
GET /repos/example-org/example-repo/issues/143/comments?per_page=100 - 500 with id UNKNOWN in 10516ms
Warning: Failed to post PR comment: Connect Timeout Error
(attempted address: github.example.com:443, timeout: 10000ms)
The 500 with id UNKNOWN entries appear to be generated by Octokit's retry plugin for the connection failure. They do not appear to represent HTTP 500 responses returned by GitHub Enterprise Server, because the underlying error is a connection timeout.
The attempted address also indicates that the client is trying to connect directly to github.example.com:443.
Expected behavior
GitHub API requests made by the action should use the proxy configured through the standard environment variables:
HTTPS_PROXYorhttps_proxyHTTP_PROXYorhttp_proxyNO_PROXYorno_proxy
If additional configuration is required, it should be documented.
Suspected cause
The reporter creates its own @octokit/rest client here:
https://github.com/ctrf-io/github-test-reporter/blob/main/src/client/github/client.ts
The client currently configures authentication, the GitHub API base URL, and retries, but it does not provide a proxy-aware request.fetch implementation or dispatcher:
const options = {
auth: GITHUB_TOKEN,
retry: {
enabled: true,
retries: 3,
},
};
According to the Octokit documentation, its API client does not use standard proxy environment variables by default. A proxy-aware fetch implementation or dispatcher must be provided:
https://github.com/octokit/octokit.js#proxy-servers-nodejs-only
For comparison, @actions/github configures Octokit with proxy-aware request handling through @actions/http-client:
- https://github.com/actions/toolkit/blob/main/packages/github/src/utils.ts
- https://github.com/actions/toolkit/blob/main/packages/github/src/internal/utils.ts
The action currently declares a Node.js 24 runtime. Node.js 24 supports HTTP_PROXY, HTTPS_PROXY, and NO_PROXY, but environment-based proxy handling must be enabled with NODE_USE_ENV_PROXY=1, --use-env-proxy, or programmatically:
- https://nodejs.org/docs/latest-v24.x/api/cli.html#--use-env-proxy
- https://nodejs.org/docs/latest-v24.x/api/http.html#built-in-proxy-support
Setting only HTTP_PROXY or HTTPS_PROXY does not automatically enable proxy handling for Node.js fetch.
Suggested solution
Please make the GitHub API client proxy-aware. Possible approaches include:
- Use the proxy-aware Octokit configuration provided by
@actions/github. - Provide Octokit with a proxy-aware
request.fetchimplementation or Undici dispatcher. - Explicitly enable Node.js environment-proxy support before creating the Octokit client.
Ideally, the implementation should support:
HTTPS_PROXYandhttps_proxyHTTP_PROXYandhttp_proxyNO_PROXYandno_proxy- HTTPS destinations through an HTTP CONNECT proxy
- Proxy authentication, if supported
- Vorherrschende Sprache
- TypeScript
- Sterne
- 376
- Forks
- 42
- PR-Merge-Kennzahlen
- Keine gemergten PRs in 30 T.
Entwicklungsumgebung
Startet den Dev-Container des Projekts im Browser, mit Ihrem eigenen GitHub-Konto.
- Kein Dockerfile und keine Docker-Compose-Datei
- Keine Pull-Request-Vorlage
- Beitragsleitfaden lesen
Erste Schritte
- Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
- Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
- Forken Sie das Repository und arbeiten Sie in einem Branch.
- Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.
Mehr aus ctrf-io/github-test-reporter
-
Schwierigkeit 3/5 1-2 Tage Anfängerfreundlichkeit 55/100
ctrf-io/github-test-reporter#309 · 1 Kommentar ·
-
Schwierigkeit 4/5 3-5 Tage Anfängerfreundlichkeit 48/100
ctrf-io/github-test-reporter#302 · 2 Kommentare ·
-
Schwierigkeit 3/5 1-2 Tage Anfängerfreundlichkeit 65/100
ctrf-io/github-test-reporter#297 · 1 Kommentar ·
-
Schwierigkeit 5/5 Über eine Woche Anfängerfreundlichkeit 45/100
ctrf-io/github-test-reporter#282 ·
-
Schwierigkeit 5/5 Über eine Woche Anfängerfreundlichkeit 45/100
ctrf-io/github-test-reporter#278 · 1 Kommentar ·
Alle Issues in ctrf-io/github-test-reporter
Ähnliche Issues
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 88/100
callstackincubator/rozenite#518 ·
Maintainer antworten meist innerhalb von 1 Tag
-
Area/Workflow Priority/Blocker Type/Bug
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 76/100
wso2/product-integrator#2622 ·
Maintainer antworten meist innerhalb von 1 Tag
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 68/100
-
area:bash bug has repro platform:macos
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 78/100
anthropics/claude-code#98644 ·
Maintainer antworten meist innerhalb von 1 Tag
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 78/100
allure-framework/allure-js#1603 ·
Maintainer antworten meist innerhalb von 1 Tag