Skip to content

ci: Skip snapshot upload when SENTRY_AUTH_TOKEN is unavailable - #6232

Closed
markushi wants to merge 3 commits into
mainfrom
ci/skip-snapshot-upload-without-auth-token
Closed

markushi wants to merge 3 commits into
mainfrom
ci/skip-snapshot-upload-without-auth-token

Conversation

@markushi

@markushi markushi commented Oct 7, 2026 •

Copy link
Copy Markdown
Member

📜 Description

The Upload Snapshots to Sentry step in build.yml had a guard that only skipped PRs from forks:

if: ${{ github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository }}

A Dependabot PR is not from a fork — its head branch lives in this repository — so the condition was
true and the step ran. But GitHub gives Dependabot workflow runs a separate secret store, so
secrets.SENTRY_AUTH_TOKEN resolved to an empty string and sentry-cli failed with HTTP 401.

This replaces the fork condition with a test on the token itself. An empty token covers both forks and
Dependabot, and the step exits successfully with a log line instead of failing the build.

💡 Motivation and Context

Every Dependabot PR failed the required Build Job ubuntu-latest - Java 17 check, which blocked the
dependency updates from merging.

Example failure — https://github.com/getsentry/sentry-java/actions/runs/37570909421/job/112661793919
(PR #6219):

error: API request failed

Caused by:
    sentry reported an error: Invalid token header. No credentials provided. (http status: 401)

💚 How did you test it?

locally

📝 Checklist

  • I added GH Issue ID & Linear ID
  • I added tests to verify the changes.
  • No new PII added or SDK only sends newly added PII if sendDefaultPII is enabled.
  • I updated the docs if needed.
  • I updated the wizard if needed.
  • Review from the native team if needed.
  • No breaking change or entry added to the changelog.
  • No breaking change for hybrid SDKs or communicated to hybrid SDKs.
  • Public API changes reviewed by another Mobile SDK team member or implemented according to the develop docs spec.

🔮 Next steps

After merge, re-run the Build job on an open Dependabot PR to confirm it goes green.

#skip-changelog

@sentry

sentry Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

📲 Install Builds

Android

🔗 App Name App ID Version Configuration
SDK Size io.sentry.tests.size 8.59.0 (1) release

⚙️ sentry-android Build Distribution Settings

@markushi markushi changed the title ci: Skip snapshot upload when SENTRY_AUTH_TOKEN is unavailable ci: Skip snapshot upload on Dependabot PRs Oct 7, 2026
@markushi markushi changed the title ci: Skip snapshot upload on Dependabot PRs ci: Skip snapshot upload when SENTRY_AUTH_TOKEN is unavailable Oct 7, 2026
@markushi
markushi marked this pull request as ready for review October 7, 2026 08:13
@runningcode

Copy link
Copy Markdown
Contributor

This is a workaround but the proper fix is to add SENTRY_AUTH_TOKEN to dependabot secrets.

@markushi

markushi commented Oct 7, 2026 •

Copy link
Copy Markdown
Member Author

This is a workaround but the proper fix is to add SENTRY_AUTH_TOKEN to dependabot secrets.

@runningcode I refrained from doing this, as a compromised dependency could then expose the auth token. Happy to discuss it further in the next sync!

Actually we need to rely on other guard rails here, as a compromised dependency has the same effect once merged. Creating a narrowly scoped token instead.

@markushi markushi closed this Oct 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants