Skip to content

Accessing draft releases is not possible using GITHUB_TOKEN in Actions #3037

Description

@mislav

Reported by @simonbrunel in #3029 (reply in thread)

To find a draft release by its tag name, we have to iterate through all releases and look into the draft ones, since there is no API endpoint to directly fetch a draft release. To avoid doing this unnecessarily when a release isn't a draft, we first check whether the viewer has write access to the repo to determine whether they can have access to drafts: #1552

This doesn't work with the generated GITHUB_TOKEN in GitHub Actions, since the viewerPermission object is null, likely due to the nature of GITHUB_TOKEN being a server-to-server integration token.

Activity

  1. added
    bugSomething isn't working
    priority-2Affects more than a few users but doesn't prevent core functions
    on Feb 24, 2021
  2. guizmaii commented on Aug 25, 2021

    @guizmaii

    Hi @mislav,

    Is there a fix for this problem? I need to access the draft releases in Github Actions but when I run gh release list, I can only see releases. 🤔

  3. mislav commented on Sep 24, 2021

    @mislav
    ContributorAuthor

    @guizmaii Sorry for the late reply. You should definitely be able to see Draft releases being listed with gh release list in Actions. But, I haven't verified this yet. Are you using secrets.GITHUB_TOKEN to authenticate?

  4. guizmaii commented on Sep 24, 2021

    @guizmaii

    Are you using secrets.GITHUB_TOKEN to authenticate?

    Yes, I am

  5. shaneharter commented on Sep 29, 2021

    @shaneharter

    I'm also having this same problem

  6. guizmaii commented on Sep 29, 2021

    @guizmaii

    @mislav can we maybe reopen this issue?

  7. mislav commented on Sep 29, 2021

    @mislav
    ContributorAuthor

    Reopening! From my testing, it looks like the GraphQL endpoint (which we use at the moment) doesn't include drafts when listing releases, while the REST does include drafts. Perhaps we should move to the REST endpoint.

    I am 90% sure that the GraphQL endpoint also listed drafts in the past when authenticated with GITHUB_TOKEN. Perhaps this regressed on the platform side at some point? I remembered this wrongly.

  8. reopened this on Sep 29, 2021
  9. added
    priority-3Affects a small number of users or is largely cosmetic
    and removed
    priority-2Affects more than a few users but doesn't prevent core functions
    on Sep 29, 2021
  10. alexcohn commented on Dec 21, 2021

    @alexcohn

    We use a draft to store some artifacts, but cannot reach them with GITHUB_TOKEN; we are forced to use personal token instead.

  11. 12 remaining items

  12. btrautmann commented on Dec 14, 2023

    @btrautmann

    I seem to be experiencing this again using GITHUB_TOKEN even with all permissions set to read. However, using an app token with read permissions on all repos in the org returns draft releases as expected.

  13. crayment commented on Jan 3, 2024

    @crayment

    I also noticed a change recently where draft releases stopped being returned using secrets.GITHUB_TOKEN

  14. Nurgak commented on Jan 15, 2024

    @Nurgak

    I'd like to report this issue as well.

    The GITHUB_TOKEN method in the CLI does not list drafts and pre-releases.

    I would also like to add that this applies to the API as well: requesting the releases via the API only lists the releases with draft and prerelease fields set to false. This functionality is very useful for testing and staging, prior to releasing in production.

  15. reopened this on Jan 16, 2024
  16. samcoe commented on Jan 16, 2024

    @samcoe
    Contributor

    Thanks all for reporting, this appears to be a regression on the platform side, I will raise this internally to see if we can get it resolved.

  17. marcin-ro commented on Feb 8, 2024

    @marcin-ro

    Hello! 👋
    @samcoe I'm sorry to bother you but did you maybe receive any information on when this might be fixed?

  18. added and removed
    more-info-neededMore info needed from user/contributor
    on Mar 22, 2024
  19. andyfeller commented on Jun 11, 2024

    @andyfeller
    Contributor

    Closing this issue as I believe the GitHub Actions and Releases teams worked out this issue some time back. #9076 (comment) demonstrates a simple workflow and the resulting output of GitHub Actions automatic token being able to list out draft releases.

  20. brandocomando commented on Mar 19, 2025

    @brandocomando

    I believe this has happening again....

  21. minkuhh commented on Apr 16, 2025

    @minkuhh

    I'm also experiencing this issue, getting this reponse in GitHub Actions:

    {
      "message": "Resource not accessible by integration",
      "documentation_url": "https://docs.github.com/rest/releases/releases#get-a-release",
      "status": "403"
    }

    The permissions I'm using are contents: read; actions: read; security-events: write;, which should work according to the endpoint's docs:

    The fine-grained token must have the following permission set:
    
    "Contents" repository permissions (read)˛
    
  22. xopham commented on Apr 24, 2025

    @xopham

    @michal-kralovic @brandocomando I think you (unintuitively) just need to use contents: write. GitHub's classification into read/write is sometimes misleading as it is more like unprivileged/privileged. Apparently, draft releases are not meant to be public and if contents: read was sufficient, any fork could access the drafts as contents: read is the restrictive default.

    That is actually in agreement with the solution shared by @andyfeller , BUT not mentioned in the API docs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workinghelp wantedContributions welcomeneeds-triageneeds to be reviewedplatformProblems with the GitHub platform rather than the CLI clientpriority-3Affects a small number of users or is largely cosmetic

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions