Skip to content

Commit 0cd3d25

Browse files
ci: rewrite git SSH to HTTPS so Dependabot e2e can install (#552)
<!-- CURSOR_AGENT_PR_BODY_BEGIN --> ## Summary Dependabot PRs fail the required `e2e` check in ~20s during `pnpm install`, not during Playwright. Automerge is already enabled; it cannot land while e2e is red. **Exact failure** (PR #482 job [96541625973](https://github.com/dripnex/app/actions/runs/32404870524/job/96541625973), also #464 / #456 / #462 and `commitlint` on #464): ``` ERROR Command failed with exit code 128: git clone git@github.com:electron/node-gyp.git ... git@github.com: Permission denied (publickey). ``` This is not missing repo secrets. Dependabot-regenerated lockfiles resolve `@electron/node-gyp` as a git dep whose `resolution.repo` is SSH: ``` # PR #456 (shell-quote) lockfile '@electron/node-gyp@git+https://git@github.com:electron/node-gyp.git#06b29aa...' resolution: {commit: 06b29aa..., repo: git@github.com:electron/node-gyp.git, type: git} # develop lockfile (e2e green after #541) '@electron/node-gyp@https://codeload.github.com/electron/node-gyp/tar.gz/06b29aa...' resolution: {tarball: https://codeload.github.com/electron/node-gyp/tar.gz/06b29aa...} ``` pnpm clones `resolution.repo` over SSH. GitHub-hosted runners have no deploy key. The `setup` job already rewrites SSH to HTTPS and therefore succeeds on the same PRs. `e2e` and `commitlint` did a fresh `pnpm install` without that rewrite. `develop` itself is green after #541 — its lockfile uses the HTTPS tarball, so e2e never hits the SSH clone. ## Type of Change - [x] Bug fix - [ ] New feature - [ ] Breaking change - [ ] Documentation update ## Fix Add the same `git config --global 'url.https://github.com/.insteadOf' 'git@github.com:'` step that `setup` / `release` / `build` / `docs` already use: - `.github/workflows/ci.yml` `e2e` job — unblocks the required e2e check - `.github/workflows/pr-title.yml` — same SSH death on Dependabot lockfiles Existing Dependabot PRs (#482, #464, #462, #460, #459, #456, #451, #431, #430, #248) should go green after rebase onto this `develop` change (the merge commit picks up the workflow). ## Related Issues Closes #544 ## Checklist - [x] I've read [CONTRIBUTING.md](../CONTRIBUTING.md) - [ ] Tests pass locally (`pnpm test`) — workflow-only change; no product code - [ ] Build succeeds (`pnpm build`) — not applicable - [x] PR targets `develop` branch (not `main`) <!-- CURSOR_AGENT_PR_BODY_END --> <div><a href="https://cursor.com/agents/bc-65d9f024-2af5-4bbe-8318-35ae4db127d2?cursor_ref=pr_footer&cursor_cta=open_in_web"><picture><source media="(prefers-color-scheme: dark)" srcset="https://cursor.com/assets/images/open-in-web-dark.png"><source media="(prefers-color-scheme: light)" srcset="https://cursor.com/assets/images/open-in-web-light.png"><img alt="Open in Web" width="114" height="28" src="https://cursor.com/assets/images/open-in-web-dark.png"></picture></a>&nbsp;<a href="https://cursor.com/background-agent?bcId=bc-65d9f024-2af5-4bbe-8318-35ae4db127d2&cursor_ref=pr_footer&cursor_cta=open_in_cursor"><picture><source media="(prefers-color-scheme: dark)" srcset="https://cursor.com/assets/images/open-in-cursor-dark.png"><source media="(prefers-color-scheme: light)" srcset="https://cursor.com/assets/images/open-in-cursor-light.png"><img alt="Open in Cursor" width="131" height="28" src="https://cursor.com/assets/images/open-in-cursor-dark.png"></picture></a>&nbsp;</div> Co-authored-by: Cursor Agent <cursoragent@cursor.com>
1 parent 2475850 commit 0cd3d25

2 files changed

Lines changed: 13 additions & 0 deletions

File tree

.github/workflows/ci.yml

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -164,6 +164,14 @@ jobs:
164164
node-version: ${{ env.NODE_VERSION }}
165165
cache: 'pnpm'
166166

167+
# Same rewrite as the setup job. Dependabot-regenerated lockfiles
168+
# resolve @electron/node-gyp as git@github.com: (SSH). Runners have
169+
# no deploy key, so install dies in ~20s with "Permission denied
170+
# (publickey)" — that is why Dependabot PRs fail e2e while develop
171+
# (HTTPS tarball in the lockfile) stays green. See #544.
172+
- name: Force HTTPS for GitHub git dependencies
173+
run: git config --global 'url.https://github.com/.insteadOf' 'git@github.com:'
174+
167175
- name: Install dependencies (with postinstall scripts)
168176
run: pnpm install --frozen-lockfile
169177

.github/workflows/pr-title.yml

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -39,6 +39,11 @@ jobs:
3939
node-version: '22'
4040
cache: 'pnpm'
4141

42+
# Dependabot lockfiles resolve @electron/node-gyp as git@github.com:.
43+
# Without this rewrite, `pnpm install` dies on SSH (see #544 / e2e).
44+
- name: Force HTTPS for GitHub git dependencies
45+
run: git config --global 'url.https://github.com/.insteadOf' 'git@github.com:'
46+
4247
# Title check only needs commitlint + its config — no workspace
4348
# native deps, no postinstall.
4449
- name: Install commitlint

0 commit comments

Comments
 (0)