fix(ci): make Docker Hub description sync non-fatal (#414)
The image build+push succeeds, but the "Update Docker Hub description" step 403s (Forbidden) — DOCKERHUB_TOKEN can push yet lacks description-edit scope, a common limitation of fine-grained Docker Hub tokens. That cosmetic overview sync was failing the whole Docker (GHCR) run on main. Mark the step continue-on-error so a creds-scope mismatch no longer reds-out an otherwise-successful build. To actually sync the overview, the token needs read/write (incl. description) scope, or use the account password. Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.8
parent
ea6833138b
commit
d674084510
@@ -118,8 +118,17 @@ jobs:
|
||||
# Sync the Docker Hub repository overview from deploy/dockerhub-overview.md.
|
||||
# Only on main pushes (the overview tracks the rolling preview) and only
|
||||
# when Docker Hub creds are present, mirroring the push gating above.
|
||||
#
|
||||
# continue-on-error: the overview text is cosmetic, and the description
|
||||
# PATCH 403s unless DOCKERHUB_TOKEN carries description-edit scope (many
|
||||
# fine-grained Docker Hub tokens that can push still can't edit the
|
||||
# description). The image build+push is what matters — a creds-scope
|
||||
# mismatch on this cosmetic step must not fail the whole Docker run. To
|
||||
# actually sync the overview, use a token with read/write (incl.
|
||||
# description) scope, or the account password.
|
||||
- name: Update Docker Hub description
|
||||
if: steps.dockerhub.outputs.enabled == 'true' && github.event_name == 'push' && github.ref == 'refs/heads/main'
|
||||
continue-on-error: true
|
||||
uses: peter-evans/dockerhub-description@v4
|
||||
with:
|
||||
username: ${{ secrets.DOCKERHUB_USERNAME }}
|
||||
|
||||
Reference in New Issue
Block a user