Skip to content

Commit bcfe6bd

Browse files
committed
workflow: fetch template_repository via REST API instead of event payload
The push event payload does not include repository.template_repository (it's a stripped-down repo object), so the previous step always emitted an empty TEMPLATE_REPO. Call the REST API with the auto-issued GITHUB_TOKEN, which is authenticated and works on private forks.
1 parent 29bb8a5 commit bcfe6bd

1 file changed

Lines changed: 10 additions & 1 deletion

File tree

‎.github/workflows/verify-stages.yml‎

Lines changed: 10 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -59,12 +59,21 @@ jobs:
5959
# Workflow-attested template lineage. karnstack's verify endpoint
6060
# prefers this over hitting the unauthenticated GitHub API, which
6161
# is required for private forks (the API call 404s on those).
62+
#
63+
# The push event payload does NOT include
64+
# repository.template_repository (it's a stripped-down version of
65+
# the repo object), so we ask the REST API directly with the
66+
# auto-issued GITHUB_TOKEN. This call is authenticated and works
67+
# on private forks.
68+
#
6269
# Trust is gated server-side by the hash check above: editing this
6370
# workflow to lie about template_repo busts the canonical hash and
6471
# the verification is rejected with `files_modified`.
72+
env:
73+
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
6574
run: |
6675
set -euo pipefail
67-
TMPL='${{ github.event.repository.template_repository.full_name }}'
76+
TMPL=$(gh api "repos/${GITHUB_REPOSITORY}" --jq '.template_repository.full_name // ""')
6877
echo "full_name=${TMPL}" >> "$GITHUB_OUTPUT"
6978
7079
- name: Mint OIDC token and post to karnstack

0 commit comments

Comments
 (0)