actions / actions/starter-workflows

Dependency submission is forbidden with sbt

Open
#2,526 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
TypeScript
Stars
12.1k
Forks
7.3k
PR merge metrics
No merged PRs in 30d

Description

By default, Scala starter workflow define an optional job that submit dependencies to GitHub API. Unfortunately, it doesn't works out of the box because of contents permission defined to read. This is well documented into this section of the README.

Here is an example of a failed job:

Run scalacenter/sbt-dependency-submission@v3
  with:
    working-directory: scala/examples
    on-resolve-failure: error
    token: ***
    sbt-plugin-version: 3.1.0
  env:
    JAVA_HOME: /opt/hostedtoolcache/Java_Temurin-Hotspot_jdk/21.0.4-7/x64
    JAVA_HOME_21_X64: /opt/hostedtoolcache/Java_Temurin-Hotspot_jdk/21.0.4-7/x64
/usr/bin/sbt --batch githubGenerateSnapshot {"ignoredModules":[],"ignoredConfigs":[],"onResolveFailure":"error","correlator":"Scala CI_build___scalacenter_sbt-dependency-submission"}; githubSubmitSnapshot
[info] welcome to sbt 1.10.2 (Eclipse Adoptium Java 21.0.4)
[info] loading settings for project examples-build from github-dependency-submission-9dbf7c50-01ca-498a-a66e-03a682e96911.sbt,plugins.sbt ...
[info] loading project definition from /home/runner/work/seblm.github.io/seblm.github.io/scala/examples/project
[info] loading settings for project root from build.sbt ...
[info] set current project to examples (in build file:/home/runner/work/seblm.github.io/seblm.github.io/scala/examples/)
[info] Resolving snapshot of scala/examples/build.sbt
[info] Setting Scala version to 3.5.1 on 1 projects.
[info] Reapplying settings...
[info] set current project to examples (in build file:/home/runner/work/seblm.github.io/seblm.github.io/scala/examples/)
[info] Including dependency graph of examples_3
[success] Total time: 2 s, completed Oct 3, 2024, 7:19:27 PM
[info] Dependency snapshot written to /tmp/dependency-snapshot-15460019313758566503.json
[info] Submitting dependency snapshot of job Job(Scala CI_build___scalacenter_sbt-dependency-submission, 11168310581, Some(https://github.com/seblm/seblm.github.io/actions/runs/11168310581)) to https://api.github.com/repos/seblm/seblm.github.io/dependency-graph/snapshots
[error] Unexpected status 403 Forbidden with body:
[error] {"message":"Resource not accessible by integration","documentation_url":"https://docs.github.com/rest/dependency-graph/dependency-submission#create-a-snapshot-of-dependencies-for-a-repository","status":"403"}
::error::Error: The process '/usr/bin/sbt' failed with exit code 1

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the linked Scala starter workflow and its optional sbt-dependency-submission job; compare its permissions with the documented 403 case in the linked README. Verify that dependency submission no longer fails with the reported 403, using the supplied job log as the baseline.

Written by the indexing model from the issue text.

Assessment

Tech stack
github-actions
Domain
ci-cd
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Clearly specified
Newbie friendliness
48/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.