From 76eab45fcc3661310c6efff188bc50bd5063adc0 Mon Sep 17 00:00:00 2001 From: Maxwell Date: Wed, 9 Sep 2026 20:20:44 +0200 Subject: [PATCH] fix(ci): allow unit tests to run on fork PRs without app secrets MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The unit-test job had create-github-app-token as its first step, which fails on pull_request events from forks because repository secrets are not available. This aborted the entire job before checkout or tests could run. Reorder: move the token step to after test execution (it only feeds the JUnit report publisher). Add continue-on-error so the token failure doesn't abort the job. When the app token is unavailable (fork PRs), fall back to the read-only GITHUB_TOKEN with annotate_only mode — the action's documented fork-PR path that annotates without creating a check run (which requires checks: write, unavailable on fork PRs). --- .github/workflows/android-ci.yml | 19 +++++++++++++------ 1 file changed, 13 insertions(+), 6 deletions(-) diff --git a/.github/workflows/android-ci.yml b/.github/workflows/android-ci.yml index cc032fc4..e5adc0f3 100644 --- a/.github/workflows/android-ci.yml +++ b/.github/workflows/android-ci.yml @@ -72,11 +72,6 @@ jobs: needs: [wrapper-validation, spotless] runs-on: ubuntu-latest steps: - - uses: actions/create-github-app-token@v3 - id: app-token - with: - client-id: ${{ secrets.APP_ID }} - private-key: ${{ secrets.APP_PRIVATE_KEY }} - name: Checkout repository uses: actions/checkout@v7 - name: Common setup @@ -86,12 +81,24 @@ jobs: ./gradlew emojify:preTest ./gradlew emojify:test --stacktrace ./gradlew emojify:postTest + - uses: actions/create-github-app-token@v3 + id: app-token + # Repository secrets are unavailable for pull_request events from forks, + # so the token step may fail there. continue-on-error keeps the job + # alive; tests must run regardless. When the app token is unavailable + # the report step falls back to the read-only GITHUB_TOKEN and uses + # annotate_only mode (no check-run creation, which needs checks: write). + continue-on-error: true + with: + client-id: ${{ secrets.APP_ID }} + private-key: ${{ secrets.APP_PRIVATE_KEY }} - name: Publish Test Report uses: mikepenz/action-junit-report@v6 if: always() with: report_paths: '**/build/test-results/**/TEST-*.xml' - token: ${{ steps.app-token.outputs.token }} + token: ${{ steps.app-token.outputs.token || github.token }} + annotate_only: ${{ steps.app-token.outputs.token == '' }} publish-artifact: name: Publish Artifact