Skip to content

Regression: gh pr create fails on self-hosted runner in v2.76.0 – “Resource not accessible by integration (organization.teams)” #11360

Description

@Pittan

Note: English isn’t my strongest skill, so I used AI to help translate this issue. If anything looks odd, please feel free to let me know!

Describe the bug

Running gh pr create inside a GitHub Actions workflow on a self-hosted runner (GitHub Enterprise Server) fails in gh v2.76.0, while the same workflow succeeds in v2.75.1.

Error message:

error fetching organization teams: GraphQL: Resource not accessible by integration (organization.teams)

Affected version

gh version 2.76.0
(v2.75.1 works as expected)

GHE 3.14.7

Steps to reproduce the behavior

  1. On a GitHub Enterprise self-hosted runner, run the following command inside a workflow or shell (authenticated with the default GITHUB_TOKEN ):
env:
  GH_ENTERPRISE_TOKEN: ${{ secrets.GITHUB_TOKEN }}
  GH_HOST: ${{ secrets.GH_HOST }}
gh pr create \
  --title "[Auto Generated] Merge chore/investigate-gh-cli-actions into release20250722" \
  --body "- This PR was automatically created by GitHub Action" \
  --base release20250722 \
  --head chore/investigate-gh-cli-actions \
  --reviewer ${{ github.event.pull_request.user.login }}
  1. Observe the CLI output.
  2. The command exits with the GraphQL error shown above.

Expected vs actual behavior

Expected – The pull request is created successfully without errors.

Actual – The command aborts with
error fetching organization teams: GraphQL: Resource not accessible by integration (organization.teams).

Logs

[git remote -v]
[git config --get-regexp ^remote\..*\.gh-resolved$]
* Request at 2025-07-22 10:57:15.645353278 +0000 UTC m=+0.106273358
* Request to https://***/api/graphql
* Request took 196.853936ms
[git config --get-regexp ^branch\.chore/investigate-gh-cli-actions\.(remote|merge|pushremote|gh-merge-base)$]
* Request at 2025-07-22 10:57:15.846370735 +0000 UTC m=+0.307290806
* Request to https://***/api/graphql
* Request took 132.334393ms
* Request at 2025-07-22 10:57:15.980077053 +0000 UTC m=+0.440997115
* Request to https://***/api/graphql
* Request at 2025-07-22 10:57:15.980144083 +0000 UTC m=+0.441064143
* Request to https://***/api/graphql
* Request at 2025-07-22 10:57:15.980191129 +0000 UTC m=+0.441111171
* Request to https://***/api/graphql
* Request took 61.681612ms
* Request took 75.983812ms
* Request took 294.085325ms
error fetching organization teams: GraphQL: Resource not accessible by integration (organization.teams)

Activity

  1. BagToad commented on Jul 22, 2025

    @BagToad
    Member

    👋 Hey @Pittan, thank you for opening this issue ✨

    I believe this was introduced in #11279, and I'm investigating and discussing with the team.

    Expand for investigation notes

    Previously we checked if any user-provided reviewer contained a / :

    	var teams []string
    	for _, r := range input.Reviewers {
    		if i := strings.IndexRune(r, '/'); i > -1 {
    			teams = append(teams, r[i+1:])
    		} else if !hasUser(r) {
    			users = append(users, r)
    		}
    	}

    This informed the query builder later to decide whether it would request teams:

        if len(teams) > 0 {
    		fmt.Fprintf(query, "organization(login:%q){\n", repo.RepoOwner())
    		for i, t := range teams {
    			fmt.Fprintf(query, "t%03d: team(slug:%q){id,slug}\n", i, t)
    		}
    		fmt.Fprint(query, "}\n")
    	}

    So the conclusion being previously we only requested teams when we believed the user input to contain them.

    Now, we always fetch the teams if we have any reviewers:

    	if input.Reviewers {
    		g.Go(func() error {
    			teams, err := OrganizationTeams(client, repo)
    			// TODO: better detection of non-org repos
    			if err != nil && !strings.Contains(err.Error(), errorResolvingOrganization) {
    				err = fmt.Errorf("error fetching organization teams: %w", err)
    				return err
    			}
    			result.Teams = teams
    			return nil
    		})
    	}

  2. self-assigned this
    on Jul 22, 2025
  3. added
    priority-2Affects more than a few users but doesn't prevent core functions
    gh-prrelating to the gh pr command
    coreThis issue is not accepting PRs from outside contributors
    and removed on Jul 22, 2025
  4. andyfeller commented on Jul 23, 2025

    @andyfeller
    Contributor

    @Pittan : a fix for this regression has been released in v2.76.1 🙇

  5. 0334-alpharaven commented on Jul 24, 2025

    @0334-alpharaven
  6. Pittan commented on Jul 24, 2025

    @Pittan
    Author

    @BagToad @andyfeller
    Thank you for your quick action 😄

  7. added a commit that references this issue on Jul 27, 2025
  8. danwulff commented on Jul 29, 2025

    @danwulff

    @BagToad @andyfeller when will this CLI update be pushed out to GitHub hosted runners? As of Jul 29, 2025 I'm still seeing version 2.76.0 of the CLI in workflows.

    Image
  9. danwulff commented on Jul 29, 2025

    @danwulff

    oh I see there's an open issue for this: actions/runner-images#12648

  10. Eldogor447-ui commented on Aug 4, 2025

    @Eldogor447-ui
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

bugSomething isn't workingcoreThis issue is not accepting PRs from outside contributorsgh-prrelating to the gh pr commandpriority-2Affects more than a few users but doesn't prevent core functions

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions