Skip to content
Commit Detail

Commit 9fd16c0

Author
Matt Kane <mkane@cloudflare.com> 2026-04-20 15:12:00 +0100
Parents
16908c9
Tree
8208ffb
Gate googlesource cookie setup on cookie presence

The current check (head.repo.fork == false) lets Dependabot PRs through
because their branches live in-repo, but Dependabot-triggered workflows
don't have access to Actions secrets. GOOGLESOURCE_COOKIE ends up empty,
yet we still rewrite chromium.googlesource.com URLs to the authenticated
/a/ endpoint, which then fails every Bazel dependency fetch with
HTTP 400.

Gate on the input being non-empty instead. This naturally covers forks
(secrets not forwarded), Dependabot (no secret access), and local runs
(no cookie at all), falling back to the unauthenticated endpoint which
is slower / rate-limited but functional.

Fixes CI on Dependabot PRs, e.g. #6418.

Files changed

1 file changed~1 modified