diff --git a/.github/workflows/simple-release.yml b/.github/workflows/simple-release.yml index 0410a45..e43a00e 100644 --- a/.github/workflows/simple-release.yml +++ b/.github/workflows/simple-release.yml @@ -20,6 +20,8 @@ env: FPM_VERSION: "1.16.0" # SSH private key for GitHub operations (populate in repository secrets) CI_CD_GH_SSH_KEY: ${{ secrets.CI_CD_GH_SSH_KEY }} + # Personal Access Token for HTTPS git operations (populate in repository secrets) + CI_CD_PAT: ${{ secrets.CI_CD_PAT }} jobs: build-windows: @@ -246,23 +248,25 @@ jobs: echo "Cloning pyenv (${PYENV_PYENV_REF}) and python-build (${PYENV_BUILD_REF}) via git (shallow)" - # Prefer SSH clones so CI can authenticate using a private key - REPO_PYENV="git@github.com:pyenv/pyenv.git" - REPO_BUILD="git@github.com:pyenv/pyenv-build.git" + # Use HTTPS clones and a repository PAT when available + REPO_PYENV="https://github.com/pyenv/pyenv.git" + REPO_BUILD="https://github.com/pyenv/pyenv-build.git" - # If a CI SSH key is provided, configure SSH for git operations - if [ -n "${CI_CD_GH_SSH_KEY:-}" ]; then - echo "Configuring SSH for GitHub using CI_CD_GH_SSH_KEY" - mkdir -p ~/.ssh - # write key and restrict permissions - printf '%s' "${CI_CD_GH_SSH_KEY}" > ~/.ssh/ci_cd_afh_adb - chmod 600 ~/.ssh/ci_cd_afh_adb - eval "$(ssh-agent -s)" - ssh-add ~/.ssh/ci_cd_afh_adb - # ensure GitHub's host key is known to avoid interactive prompt - ssh-keyscan github.com >> ~/.ssh/known_hosts + EXTRA_HEADER="" + if [ -n "${CI_CD_PAT:-}" ]; then + echo "Configuring git to use CI_CD_PAT for HTTPS operations" + # Create Authorization header: Basic base64(:PAT) + EXTRA_HEADER="AUTHORIZATION: basic $(printf ':%s' "${CI_CD_PAT}" | base64)" fi + gitx() { + if [ -n "${EXTRA_HEADER}" ]; then + git -c http.extraHeader="${EXTRA_HEADER}" "$@" + else + git "$@" + fi + } + # pyenv: shallow clone the requested ref if possible, otherwise fall back to default shallow clone if [ -d "$PYENV_ROOT/.git" ]; then retry git -C "$PYENV_ROOT" fetch --all --prune --depth=1 || true