Remove the redundant GITHUB_TOKEN ref-existence check - #14
Merged
Conversation
GITHUB_TOKEN was only consulted by the manual POST /-/refs endpoint to verify a commit exists before registering it. The supported integration path is the publish action (POST /-/publish), which never uses it, and the token was optional and unset in production. Drop GITHUB_TOKEN from env.ts and the Env interface, delete src/github/verifyRef.ts and its unit test, strip the verification branch from POST /-/refs, and update the docs.
fengmk2
force-pushed
the
remove-github-token
branch
from
June 28, 2026 16:35
a611cb6 to
6528feb
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
GITHUB_TOKENwas only consulted by the manualPOST /-/refsendpoint (viaverifyRefExists) to check a commit exists before registering its ref. The supported path is the CI publish action (POST /-/publish), which never uses it; the token was optional and unset in production; andvite-plusis public so the existence check needs no auth anyway.Removes:
GITHUB_TOKENfromenv.ts+Env,src/github/verifyRef.tsand its unit test, the verification branch inPOST /-/refs, and the doc references.POST /-/refsstill registers refs (admin-guarded); it just no longer does the optional GitHub existence check. typecheck clean, 54 tests pass.