From d674084510e55ea9ed5fd96534c7191663dcbc7b Mon Sep 17 00:00:00 2001 From: Palash Debnath Date: Sat, 13 Jun 2026 14:59:32 +0530 Subject: [PATCH] fix(ci): make Docker Hub description sync non-fatal (#414) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The image build+push succeeds, but the "Update Docker Hub description" step 403s (Forbidden) — DOCKERHUB_TOKEN can push yet lacks description-edit scope, a common limitation of fine-grained Docker Hub tokens. That cosmetic overview sync was failing the whole Docker (GHCR) run on main. Mark the step continue-on-error so a creds-scope mismatch no longer reds-out an otherwise-successful build. To actually sync the overview, the token needs read/write (incl. description) scope, or use the account password. Co-authored-by: Claude Opus 4.8 (1M context) --- .github/workflows/docker.yml | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/.github/workflows/docker.yml b/.github/workflows/docker.yml index fc2daa86..f1fe6358 100644 --- a/.github/workflows/docker.yml +++ b/.github/workflows/docker.yml @@ -118,8 +118,17 @@ jobs: # Sync the Docker Hub repository overview from deploy/dockerhub-overview.md. # Only on main pushes (the overview tracks the rolling preview) and only # when Docker Hub creds are present, mirroring the push gating above. + # + # continue-on-error: the overview text is cosmetic, and the description + # PATCH 403s unless DOCKERHUB_TOKEN carries description-edit scope (many + # fine-grained Docker Hub tokens that can push still can't edit the + # description). The image build+push is what matters — a creds-scope + # mismatch on this cosmetic step must not fail the whole Docker run. To + # actually sync the overview, use a token with read/write (incl. + # description) scope, or the account password. - name: Update Docker Hub description if: steps.dockerhub.outputs.enabled == 'true' && github.event_name == 'push' && github.ref == 'refs/heads/main' + continue-on-error: true uses: peter-evans/dockerhub-description@v4 with: username: ${{ secrets.DOCKERHUB_USERNAME }}