Repository navigation
Conversation
📲 Install BuildsAndroid
|
markushi
marked this pull request as ready for review
October 7, 2026 08:13
markushi
requested review from
0xadam-brown,
adinauer,
romtsn and
runningcode
as code owners
October 7, 2026 08:13
Contributor
|
This is a workaround but the proper fix is to add SENTRY_AUTH_TOKEN to dependabot secrets. |
Member
Author
Actually we need to rely on other guard rails here, as a compromised dependency has the same effect once merged. Creating a narrowly scoped token instead. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
📜 Description
The
Upload Snapshots to Sentrystep inbuild.ymlhad a guard that only skipped PRs from forks:A Dependabot PR is not from a fork — its head branch lives in this repository — so the condition was
true and the step ran. But GitHub gives Dependabot workflow runs a separate secret store, so
secrets.SENTRY_AUTH_TOKENresolved to an empty string andsentry-clifailed with HTTP 401.This replaces the fork condition with a test on the token itself. An empty token covers both forks and
Dependabot, and the step exits successfully with a log line instead of failing the build.
💡 Motivation and Context
Every Dependabot PR failed the required
Build Job ubuntu-latest - Java 17check, which blocked thedependency updates from merging.
Example failure — https://github.com/getsentry/sentry-java/actions/runs/37570909421/job/112661793919
(PR #6219):
💚 How did you test it?
locally
📝 Checklist
sendDefaultPIIis enabled.🔮 Next steps
After merge, re-run the Build job on an open Dependabot PR to confirm it goes green.
#skip-changelog