FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

Protected branch update failed · Issue #739 · python-semantic-release/python-semantic-release · GitHub

Repository navigation

Protected branch update failed #739

Description

I'm in the process of setting up python-semantic-release for one of my repositories.

Since I need Python 3.11, I can not use the dockerized GitHub Action and use the following instead:

  release:
    name: Release
    if: github.event_name == 'push' && github.ref == 'refs/heads/main' && !contains(github.event.head_commit.message, 'chore(release):')
    runs-on: ubuntu-latest
    concurrency: release
    permissions:
      id-token: write
      contents: write
    steps:
      - name: Check out repository
        uses: actions/checkout@v4
        with:
          fetch-depth: 0

      - name: Setup Python 3.11
        uses: actions/setup-python@v4
        with:
          python-version: "3.11"

      - name: Install python-semantic-release
        run: |
          pip install python-semantic-release

      - name: Semantic release
        env:
          GH_TOKEN: ${{ secrets.GH_SEMREL }}
        run: |
          semantic-release version

GH_SEMREL contains a "classic" PAT with the repo scope.

But I still only get the message

...
    raise GitCommandError(redacted_command, status, stderr_value, stdout_value)
git.exc.GitCommandError: Cmd('git') failed due to: exit code(1)
  cmdline: git push ***github.com/***/***.git main
  stderr: 'remote: error: GH006: Protected branch update failed for refs/heads/main.        
remote: error: Changes must be made through a pull request.        
To https://github.com/***/***.git
 ! [remote rejected] main -> main (protected branch hook declined)
error: failed to push some refs to 'https://github.com/***/***.git''
Error: Process completed with exit code 1.

What am I doing wrong?

Activity

  1. zckv commented on Oct 24, 2023

    Contributor

    Hello 👋

    The GitHub Action is not dockerized anymore ! You should try to use it 😄

    I think you have a branch protection rule that block all tries to push on the branch main. Verify this in PROJECT/settings/branches.
    Since python-semantic-release push to the main branch and tag the commit, it blocks if it is unable to.

  2. eikowagenknecht commented on Oct 24, 2023

    Author

    Hey! It seems like you implemented a Docker-free version in #692, which was unfortunately reverted as of 22 minutes ago. I'll try it when it's available again :-)

    You are correct, I have a branch protection rule. And the default GITHUB_TOKEN has no rights to access a protected branch, so the message is correct.

    But I read in other threads here, that it should be possible to not use the default token but a PAT (Personal Access Token) with repo scope which then is able to access a protected branch.

    That's exactly what I was trying to do with the GH_SEMREL token and the GH_TOKEN: ${{ secrets.GH_SEMREL }} line. The GH_SEMREL token contains a PAT with the repo scope.

    I created the token in my account > Settings > Developer Settings:

    and pasted the resulting token into the GH_SEMREL secret in my project's settings:

    // EDIT: I get the same results with this:

          - name: Semantic Release
            uses: python-semantic-release/python-semantic-release@v8.3.0
            with:
              github_token: ${{ secrets.GH_SEMREL }}
    
  3. bernardcooke53 commented on Oct 24, 2023

    Contributor

    Hey @eikowagenknecht,

    Yes I had to revert the docker-free version of the action as it needs a few extra things. Have you tried following this advice?

    The gist is essentially allowing specified users (e.g. the one whose account was used to generate the PAT) to bypass branch protection rules.

    If you want to get a faster feedback loop, you can try this locally:

    # starting with some throwaway repo and/or throwaway protected branch
    export GIT_BRANCH=<throwaway branch and/or main>
    git commit --allow-empty -m "test commit"
    # ensure this fails with "protected branch hook declined"
    git push -u origin $GIT_BRANCH
    
    git remote set-url origin https://x-access-token:$GITHUB_PAT@github.com/eikowagenknecht/<your repo>
    git commit --allow-empty -m "another test commit"
    # this should succeed
    git push -u origin $GIT_BRANCH

    if you can get the token to work with the above then it should also work in a workflow run. Unfortunately I believe in order to bypass the branch protection rule the user has to have the "Administrator" role, unless your repo allows for lower privilege roles to bypass the rule (with the "Restrict who can push to matching branches" field of the branch protection rule).

  4. TomDarmon commented on Nov 8, 2023

    I have the same issue, I get the same error:

    ! [remote rejected] main -> main (protected branch hook declined)
    error: failed to push some refs to 'https://github.com/***/***.git''
    Error: Process completed with exit code 1.

    But I've created a token with the writes to push code using my admin account who can bypass the branch rules. Is there any workaround ?

  5. zckv commented on Nov 10, 2023

    Contributor
  6. eikowagenknecht commented on Nov 14, 2023

    Author

    Thanks for the detailed descriptions @bernardcooke53! I found a suggested solution in the link @zckv provided: https://github.com/orgs/community/discussions/25305#discussioncomment-5582031

    It seems that the checkout action persists the token, so the PAT needs to be placed there and not in the python-semantic-release action itself.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions


      Back | FazBrowse Home | New Git URL