From 22284b1ade27612f7e5226ee0d2e827d76b5bcae Mon Sep 17 00:00:00 2001 From: Cursor Agent Date: Sat, 6 Jun 2026 16:05:28 +0000 Subject: [PATCH] ci: authenticate git push in daily branch workflows The zizmor remediation in PR #24663 added 'persist-credentials: false' to the checkout step but the workflow still relies on 'git push origin' inheriting credentials from the global git config. Without persisted credentials, the push fails with 'could not read Username for github.com' and the scheduled job has been failing every run since. Push directly to the authenticated HTTPS URL using GITHUB_TOKEN so the checkout step can keep persist-credentials disabled (no token in git config) while the push still works. Co-authored-by: Krrish Dholakia --- .github/workflows/create_daily_oss_agent_shin_branch.yml | 4 +--- .github/workflows/create_daily_staging_branch.yml | 8 ++------ 2 files changed, 3 insertions(+), 9 deletions(-) diff --git a/.github/workflows/create_daily_oss_agent_shin_branch.yml b/.github/workflows/create_daily_oss_agent_shin_branch.yml index d6118f3b53c..aabb7801204 100644 --- a/.github/workflows/create_daily_oss_agent_shin_branch.yml +++ b/.github/workflows/create_daily_oss_agent_shin_branch.yml @@ -39,9 +39,7 @@ jobs: echo "Branch $BRANCH_NAME already exists. Skipping creation." else echo "Creating new branch: $BRANCH_NAME" - # Create the new branch from main git checkout -b $BRANCH_NAME origin/main - # Push the new branch - git push origin $BRANCH_NAME + git push "https://x-access-token:${GITHUB_TOKEN}@github.com/${GITHUB_REPOSITORY}.git" "$BRANCH_NAME" echo "Successfully created and pushed branch: $BRANCH_NAME" fi diff --git a/.github/workflows/create_daily_staging_branch.yml b/.github/workflows/create_daily_staging_branch.yml index 424d8de0a41..0ee88bdadc5 100644 --- a/.github/workflows/create_daily_staging_branch.yml +++ b/.github/workflows/create_daily_staging_branch.yml @@ -39,10 +39,8 @@ jobs: echo "Branch $BRANCH_NAME already exists. Skipping creation." else echo "Creating new branch: $BRANCH_NAME" - # Create the new branch from main git checkout -b $BRANCH_NAME origin/main - # Push the new branch - git push origin $BRANCH_NAME + git push "https://x-access-token:${GITHUB_TOKEN}@github.com/${GITHUB_REPOSITORY}.git" "$BRANCH_NAME" echo "Successfully created and pushed branch: $BRANCH_NAME" fi @@ -79,9 +77,7 @@ jobs: echo "Branch $BRANCH_NAME already exists. Skipping creation." else echo "Creating new branch: $BRANCH_NAME" - # Create the new branch from main git checkout -b $BRANCH_NAME origin/main - # Push the new branch - git push origin $BRANCH_NAME + git push "https://x-access-token:${GITHUB_TOKEN}@github.com/${GITHUB_REPOSITORY}.git" "$BRANCH_NAME" echo "Successfully created and pushed branch: $BRANCH_NAME" fi