Commit Detail
Commit 9fd16c0
Gate googlesource cookie setup on cookie presence The current check (head.repo.fork == false) lets Dependabot PRs through because their branches live in-repo, but Dependabot-triggered workflows don't have access to Actions secrets. GOOGLESOURCE_COOKIE ends up empty, yet we still rewrite chromium.googlesource.com URLs to the authenticated /a/ endpoint, which then fails every Bazel dependency fetch with HTTP 400. Gate on the input being non-empty instead. This naturally covers forks (secrets not forwarded), Dependabot (no secret access), and local runs (no cookie at all), falling back to the unauthenticated endpoint which is slower / rate-limited but functional. Fixes CI on Dependabot PRs, e.g. #6418.
Files changed
1 file changed~1 modified