Repository navigation
Accessing draft releases is not possible using GITHUB_TOKEN in Actions #3037
Description
Activity
- addedbugSomething isn't workingSomething isn't workingpriority-2Affects more than a few users but doesn't prevent core functionsAffects more than a few users but doesn't prevent core functions
on Feb 24, 2021 - added a commit that references this issue
on May 17, 2021 Hi @mislav,
Is there a fix for this problem? I need to access the draft releases in Github Actions but when I run
gh release list, I can only see releases. 🤔@guizmaii Sorry for the late reply. You should definitely be able to see Draft releases being listed with
gh release listin Actions. But, I haven't verified this yet. Are you usingsecrets.GITHUB_TOKENto authenticate?Are you using secrets.GITHUB_TOKEN to authenticate?
Yes, I am
I'm also having this same problem
@mislav can we maybe reopen this issue?
Reopening! From my testing, it looks like the GraphQL endpoint (which we use at the moment) doesn't include drafts when listing releases, while the REST does include drafts. Perhaps we should move to the REST endpoint.
I am 90% sure that the GraphQL endpoint also listed drafts in the past when authenticated with GITHUB_TOKEN. Perhaps this regressed on the platform side at some point?I remembered this wrongly.Reacted by Jules Ivanic and Alex Cohn- addedhelp wantedContributions welcomeContributions welcomepriority-3Affects a small number of users or is largely cosmeticAffects a small number of users or is largely cosmeticand removedpriority-2Affects more than a few users but doesn't prevent core functionsAffects more than a few users but doesn't prevent core functions
on Sep 29, 2021 We use a draft to store some artifacts, but cannot reach them with GITHUB_TOKEN; we are forced to use personal token instead.
Reacted by Jules Ivanic12 remaining items
I seem to be experiencing this again using
GITHUB_TOKENeven with all permissions set toread. However, using an app token with read permissions on all repos in the org returns draft releases as expected.Reacted by Cody Rayment and Han QiaoI also noticed a change recently where draft releases stopped being returned using
secrets.GITHUB_TOKENReacted by Brandon Trautmann, Alexander Dupuy and Han QiaoI'd like to report this issue as well.
The
GITHUB_TOKENmethod in the CLI does not list drafts and pre-releases.I would also like to add that this applies to the API as well: requesting the releases via the API only lists the releases with
draftandprereleasefields set tofalse. This functionality is very useful for testing and staging, prior to releasing in production.Reacted by Han Qiao and Robert BurkeThanks all for reporting, this appears to be a regression on the platform side, I will raise this internally to see if we can get it resolved.
Reacted by Brandon Trautmann, meleu-cw, Alexander Dupuy and Han QiaoHello! 👋
@samcoe I'm sorry to bother you but did you maybe receive any information on when this might be fixed?- addedneeds-triageneeds to be reviewedneeds to be reviewedand removedmore-info-neededMore info needed from user/contributorMore info needed from user/contributor
on Mar 22, 2024 Closing this issue as I believe the GitHub Actions and Releases teams worked out this issue some time back. #9076 (comment) demonstrates a simple workflow and the resulting output of GitHub Actions automatic token being able to list out draft releases.
I believe this has happening again....
I'm also experiencing this issue, getting this reponse in GitHub Actions:
{ "message": "Resource not accessible by integration", "documentation_url": "https://docs.github.com/rest/releases/releases#get-a-release", "status": "403" }The permissions I'm using are
contents: read; actions: read; security-events: write;, which should work according to the endpoint's docs:The fine-grained token must have the following permission set: "Contents" repository permissions (read)˛@michal-kralovic @brandocomando I think you (unintuitively) just need to use
contents: write. GitHub's classification into read/write is sometimes misleading as it is more like unprivileged/privileged. Apparently, draft releases are not meant to be public and ifcontents: readwas sufficient, any fork could access the drafts ascontents: readis the restrictive default.That is actually in agreement with the solution shared by @andyfeller , BUT not mentioned in the API docs.
Reacted by Andy Feller and Brandon Foster- added a commit that references this issue
on Aug 5, 2026 - added a commit that references this issue
on Aug 29, 2026
Reported by @simonbrunel in #3029 (reply in thread)
To find a draft release by its tag name, we have to iterate through all releases and look into the draft ones, since there is no API endpoint to directly fetch a draft release. To avoid doing this unnecessarily when a release isn't a draft, we first check whether the viewer has write access to the repo to determine whether they can have access to drafts: #1552
This doesn't work with the generated GITHUB_TOKEN in GitHub Actions, since the
viewerPermissionobject is null, likely due to the nature of GITHUB_TOKEN being a server-to-server integration token.