Add env: GITHUB_TOKEN to the Linux workflow step, then read it in ci/main.go and inject it into each test container via WithSecretVariable (for both GITHUB_TOKEN and GH_TOKEN). This prevents 403 rate-limit errors on GitHub API calls (neovim/nvm releases) and authenticates gh CLI for gh extension install inside the containers. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>