diff --git a/.github/workflows/ci-doctor.lock.yml b/.github/workflows/ci-doctor.lock.yml index 0d4e84bde..cfc6d8361 100644 --- a/.github/workflows/ci-doctor.lock.yml +++ b/.github/workflows/ci-doctor.lock.yml @@ -1263,10 +1263,6 @@ jobs: env: GH_AW_WORKFLOW_ID_SANITIZED: cidoctor steps: - - name: Setup Scripts - uses: github/gh-aw/actions/setup@v0.50.5 - with: - destination: /opt/gh-aw/actions - name: Download cache-memory artifact (default) id: download_cache_default uses: actions/download-artifact@018cc2cf5baa6db3ef3c5f8a56943fffe632ef53 # v6 diff --git a/.github/workflows/issue-duplication-detector.lock.yml b/.github/workflows/issue-duplication-detector.lock.yml index 5944b60e4..693634286 100644 --- a/.github/workflows/issue-duplication-detector.lock.yml +++ b/.github/workflows/issue-duplication-detector.lock.yml @@ -1115,10 +1115,6 @@ jobs: runs-on: ubuntu-latest permissions: {} steps: - - name: Setup Scripts - uses: github/gh-aw/actions/setup@v0.47.0 - with: - destination: /opt/gh-aw/actions - name: Download cache-memory artifact (default) id: download_cache_default uses: actions/download-artifact@018cc2cf5baa6db3ef3c5f8a56943fffe632ef53 # v6 diff --git a/.github/workflows/pelis-agent-factory-advisor.lock.yml b/.github/workflows/pelis-agent-factory-advisor.lock.yml index 89c249611..2c1d8220f 100644 --- a/.github/workflows/pelis-agent-factory-advisor.lock.yml +++ b/.github/workflows/pelis-agent-factory-advisor.lock.yml @@ -1142,10 +1142,6 @@ jobs: runs-on: ubuntu-latest permissions: {} steps: - - name: Setup Scripts - uses: github/gh-aw/actions/setup@v0.47.0 - with: - destination: /opt/gh-aw/actions - name: Download cache-memory artifact (default) id: download_cache_default uses: actions/download-artifact@018cc2cf5baa6db3ef3c5f8a56943fffe632ef53 # v6 diff --git a/.github/workflows/secret-digger-claude.lock.yml b/.github/workflows/secret-digger-claude.lock.yml index 26765e717..e765b8e4a 100644 --- a/.github/workflows/secret-digger-claude.lock.yml +++ b/.github/workflows/secret-digger-claude.lock.yml @@ -1193,10 +1193,6 @@ jobs: runs-on: ubuntu-latest permissions: {} steps: - - name: Setup Scripts - uses: github/gh-aw/actions/setup@v0.47.0 - with: - destination: /opt/gh-aw/actions - name: Download cache-memory artifact (default) id: download_cache_default uses: actions/download-artifact@018cc2cf5baa6db3ef3c5f8a56943fffe632ef53 # v6 diff --git a/.github/workflows/secret-digger-codex.lock.yml b/.github/workflows/secret-digger-codex.lock.yml index 1fa5eb002..3464d452d 100644 --- a/.github/workflows/secret-digger-codex.lock.yml +++ b/.github/workflows/secret-digger-codex.lock.yml @@ -1130,10 +1130,6 @@ jobs: runs-on: ubuntu-latest permissions: {} steps: - - name: Setup Scripts - uses: github/gh-aw/actions/setup@v0.47.0 - with: - destination: /opt/gh-aw/actions - name: Download cache-memory artifact (default) id: download_cache_default uses: actions/download-artifact@018cc2cf5baa6db3ef3c5f8a56943fffe632ef53 # v6 diff --git a/.github/workflows/secret-digger-copilot.lock.yml b/.github/workflows/secret-digger-copilot.lock.yml index c15d4167c..b3ce66e71 100644 --- a/.github/workflows/secret-digger-copilot.lock.yml +++ b/.github/workflows/secret-digger-copilot.lock.yml @@ -1129,10 +1129,6 @@ jobs: runs-on: ubuntu-latest permissions: {} steps: - - name: Setup Scripts - uses: github/gh-aw/actions/setup@v0.47.0 - with: - destination: /opt/gh-aw/actions - name: Download cache-memory artifact (default) id: download_cache_default uses: actions/download-artifact@018cc2cf5baa6db3ef3c5f8a56943fffe632ef53 # v6 diff --git a/.github/workflows/security-review.lock.yml b/.github/workflows/security-review.lock.yml index d27c4affa..ffe1cc293 100644 --- a/.github/workflows/security-review.lock.yml +++ b/.github/workflows/security-review.lock.yml @@ -1143,10 +1143,6 @@ jobs: runs-on: ubuntu-latest permissions: {} steps: - - name: Setup Scripts - uses: github/gh-aw/actions/setup@v0.47.0 - with: - destination: /opt/gh-aw/actions - name: Download cache-memory artifact (default) id: download_cache_default uses: actions/download-artifact@018cc2cf5baa6db3ef3c5f8a56943fffe632ef53 # v6 diff --git a/.github/workflows/smoke-claude.lock.yml b/.github/workflows/smoke-claude.lock.yml index c0fa7c35a..64bb70081 100644 --- a/.github/workflows/smoke-claude.lock.yml +++ b/.github/workflows/smoke-claude.lock.yml @@ -1256,10 +1256,6 @@ jobs: runs-on: ubuntu-latest permissions: {} steps: - - name: Setup Scripts - uses: github/gh-aw/actions/setup@v0.47.0 - with: - destination: /opt/gh-aw/actions - name: Download cache-memory artifact (default) id: download_cache_default uses: actions/download-artifact@018cc2cf5baa6db3ef3c5f8a56943fffe632ef53 # v6 diff --git a/.github/workflows/smoke-codex.lock.yml b/.github/workflows/smoke-codex.lock.yml index 20bff8060..83a7a0ea7 100644 --- a/.github/workflows/smoke-codex.lock.yml +++ b/.github/workflows/smoke-codex.lock.yml @@ -1836,10 +1836,6 @@ jobs: runs-on: ubuntu-latest permissions: {} steps: - - name: Setup Scripts - uses: github/gh-aw/actions/setup@v0.47.0 - with: - destination: /opt/gh-aw/actions - name: Download cache-memory artifact (default) id: download_cache_default uses: actions/download-artifact@018cc2cf5baa6db3ef3c5f8a56943fffe632ef53 # v6 diff --git a/.github/workflows/smoke-copilot.lock.yml b/.github/workflows/smoke-copilot.lock.yml index 9cf4a1ed6..1589b6243 100644 --- a/.github/workflows/smoke-copilot.lock.yml +++ b/.github/workflows/smoke-copilot.lock.yml @@ -1186,10 +1186,6 @@ jobs: runs-on: ubuntu-latest permissions: {} steps: - - name: Setup Scripts - uses: github/gh-aw/actions/setup@v0.47.0 - with: - destination: /opt/gh-aw/actions - name: Download cache-memory artifact (default) id: download_cache_default uses: actions/download-artifact@018cc2cf5baa6db3ef3c5f8a56943fffe632ef53 # v6 diff --git a/scripts/ci/postprocess-smoke-workflows.ts b/scripts/ci/postprocess-smoke-workflows.ts index 5d34745c9..3f2711ddf 100644 --- a/scripts/ci/postprocess-smoke-workflows.ts +++ b/scripts/ci/postprocess-smoke-workflows.ts @@ -87,6 +87,14 @@ const shallowDepthRegex = /^(\s+)depth: 1\n/gm; // instead of pre-built GHCR images that may be stale. const imageTagRegex = /--image-tag\s+[0-9.]+\s+--skip-pull/g; +// Remove the "Setup Scripts" step from update_cache_memory jobs. +// This step downloads the private github/gh-aw action but is never used in +// update_cache_memory (no subsequent steps reference /opt/gh-aw/actions/). +// With permissions: {} on these jobs, downloading the private action fails +// with 401 Unauthorized. +const updateCacheSetupScriptRegex = + /^(\s+)- name: Setup Scripts\n\1 uses: github\/gh-aw\/actions\/setup@v[\d.]+\n\1 with:\n\1 destination: \/opt\/gh-aw\/actions\n(\1- name: Download cache-memory artifact)/gm; + for (const workflowPath of workflowPaths) { let content = fs.readFileSync(workflowPath, 'utf-8'); let modified = false; @@ -132,6 +140,18 @@ for (const workflowPath of workflowPaths) { console.log(` Replaced ${imageTagMatches.length} --image-tag/--skip-pull with --build-local`); } + // Remove unused "Setup Scripts" step from update_cache_memory jobs. + // The step downloads a private action but is never used in these jobs, + // causing 401 Unauthorized failures when permissions: {} is set. + const updateCacheSetupMatches = content.match(updateCacheSetupScriptRegex); + if (updateCacheSetupMatches) { + content = content.replace(updateCacheSetupScriptRegex, '$2'); + modified = true; + console.log( + ` Removed ${updateCacheSetupMatches.length} unused Setup Scripts step(s) from update_cache_memory` + ); + } + if (modified) { fs.writeFileSync(workflowPath, content); console.log(`Updated ${workflowPath}`);