fix: use authenticated GitHub API requests to avoid rate limiting - #32
Merged
Conversation
The install step fetches release checksums from the GitHub API using unauthenticated requests, which are limited to 60 req/hr per IP. Since GitHub Actions runners share IPs, this limit is frequently hit. Add a github-token input and fall back to GITHUB_TOKEN env var to make authenticated requests (5,000 req/hr), preventing rate limit errors.
🦋 Changeset detectedLatest commit: 5234f13 The changes in this PR will be included in the next version bump. This PR includes changesets to release 1 package
Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
Updated to use authenticated GitHub API requests to prevent rate limiting issues.
mikesutormin
approved these changes
Mar 19, 2026
davestepanyan
approved these changes
Mar 19, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
github-tokeninput to the action for authenticated GitHub API requestsGITHUB_TOKENenv var (automatically available in GitHub Actions)Problem
The
install()step makes unauthenticated requests toapi.github.comto fetch release checksums for the ejsonkms binary. Unauthenticated requests are limited to 60 req/hr per IP. Since GitHub Actions runners share IPs, this limit is hit frequently, causingHttpClientError: API rate limit exceededfailures.Solution
Use the GitHub token (from the new
github-tokeninput orGITHUB_TOKENenv var) to make authenticated requests, which have a 5,000 req/hr rate limit.Backwards compatible - the new input is optional, and the action falls back to
process.env.GITHUB_TOKENwhich is already present in GitHub Actions runners.