Skip to content

WinGet publishing fails on every stable release since v1.12.0 (CreateRef permission denied) #757

Description

@EtienneLescot

publish-winget.yml has failed on every stable release since v1.12.0: v1.12.0, v1.12.1, v1.12.2 and v1.13.0 (run 36000771103). The failing step is vedantmgoyal9/winget-releaser (komac):

0: EtienneLescot does not have the correct permissions to execute `CreateRef`
1: failed to create branch OpenScreen.OpenScreen-1.13.0-5EF7C8FAFFC34DCD89665971980B4936

What is already in place (so this is no longer the "not configured" case #148 was about):

  • WINGET_IDENTIFIER = OpenScreen.OpenScreen, and WINGET_ACC_TOKEN is set; the run gets past the configuration check.
  • A fork exists under the org: getopenscreen/winget-pkgs. There is also a personal fork, EtienneLescot/winget-pkgs, last pushed 2026-08-11.
  • The package exists upstream, so the "first manifest must be manual" prerequisite is met. microsoft/winget-pkgs has 1.9.2, 1.9.6, 1.10.0 (submitted by hand), plus 1.11.0 and 1.12.2 (pushed by the community bot damn-good-b0t, not by us). 1.12.0, 1.12.1 and 1.13.0 are missing. 1.10.0 also needed a follow-up InstallerSha256 fix (#423711 upstream).

Likely cause, to confirm: the action's fork-user defaults to the repository owner (getopenscreen), so komac tries to create a branch in getopenscreen/winget-pkgs with a token that belongs to EtienneLescot. A CreateRef denial with a valid token points at one of three things:

  • the token's scopes, since it must be a classic PAT with public_repo;
  • an org policy restricting classic PATs on getopenscreen;
  • fork-user pointing at a fork the token cannot write to.

Also stale: technical-documentation/engineering/release-and-secrets.md still says WINGET_ACC_TOKEN is absent. The workflow's warning text still lists prerequisites that are now met.

Expected: a stable release lands in microsoft/winget-pkgs through our workflow, and a failure names the actual missing permission instead of a generic komac error.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions