From f645e513382a5934878f033ecef9ed3bc27fde27 Mon Sep 17 00:00:00 2001 From: Mihir Kandoi Date: Mon, 29 Jun 2026 21:33:42 +0530 Subject: [PATCH] ci(patch): fetch v14 baseline from public release URL without a token MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Greptile flagged that `gh release download` with `github.token` could be rejected for fork pull requests (token scoped to the fork, asset in frappe/erpnext). The release is public and published, so the asset is downloadable anonymously from objects.githubusercontent.com — drop the token and curl the public URL directly. Removes the cross-repo token dependency and keeps fork PRs working. Cloudflare is still bypassed since GitHub serves the asset, not frappe.io. Co-Authored-By: Claude Opus 4.8 --- .github/workflows/patch.yml | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/.github/workflows/patch.yml b/.github/workflows/patch.yml index 24c767023a8..83c2d7ff925 100644 --- a/.github/workflows/patch.yml +++ b/.github/workflows/patch.yml @@ -76,9 +76,10 @@ jobs: - name: Download erpnext v14 backup if: steps.cache-v14.outputs.cache-hit != 'true' - run: gh release download v14-baseline -R frappe/erpnext -p erpnext-v14.sql.gz -O ~/erpnext-v14.sql.gz - env: - GH_TOKEN: ${{ github.token }} + run: | + curl -fSL --retry 5 --retry-all-errors --retry-delay 5 \ + -o ~/erpnext-v14.sql.gz \ + https://github.com/frappe/erpnext/releases/download/v14-baseline/erpnext-v14.sql.gz - name: Cache pip uses: actions/cache@v4