Skip to content

ci: read-only token for the native job, not kept in the checkout - #81

Closed
bgrana75 wants to merge 3 commits into
rferrari:fullnative-devfrom
bgrana75:ci/native-engine-sdk
Closed

bgrana75 wants to merge 3 commits into
rferrari:fullnative-devfrom
bgrana75:ci/native-engine-sdk

Conversation

@bgrana75

@bgrana75 bgrana75 commented Oct 10, 2026 •

Copy link
Copy Markdown

CI: read-only token for the native job, not kept in the checkout

Your 40c2c623 fixed the setup-android failure on fullnative-dev (only platform-tools), so this PR no longer changes the SDK step. I merged fullnative-dev in and kept your version.

What's left is CodeRabbit's finding from its review of #80: the native-engine job runs the pull request's own Gradle code, and actions/checkout keeps GITHUB_TOKEN in the checkout. Two lines limit that:

  • permissions: contents: read on the job;
  • persist-credentials: false on the checkout. The submodules are still fetched by the checkout step itself.

The job's own run on this PR is the check. No CodeRabbit CLI review was run before pushing (cr isn't installed here).

android-actions/setup-android@v3 failed before any build: its default packages are "tools
platform-tools", and the SDK repository no longer has "tools" (sdkmanager: Failed to find package
'tools', exit code 1). The Ubuntu runner already has the Android SDK, so the job now accepts the
licenses and installs the pinned NDK and CMake with $ANDROID_HOME/cmdline-tools/latest/bin/sdkmanager.
@coderabbitai

coderabbitai Bot commented Oct 10, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 572493c2-d93c-446e-b508-f7d8a9203faa

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@bgrana75

Copy link
Copy Markdown
Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Oct 10, 2026 •

Copy link
Copy Markdown
⚠️ Action not completed

Review rate limited.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

The job runs the pull request's Gradle code. permissions: contents: read, and checkout with
persist-credentials: false (CodeRabbit review on rferrari#80).
…ngine-sdk

# Conflicts:
#	.github/workflows/ci.yml
@bgrana75 bgrana75 changed the title ci: install the NDK with the runner's own sdkmanager ci: read-only token for the native job, not kept in the checkout Oct 10, 2026
@rferrari

Copy link
Copy Markdown
Owner

Thanks. The same two lines landed on fullnative-dev in c2c5ca0 (after #80 merged), so this
now only differs in a comment and conflicts with the branch. Closing as a duplicate.

@rferrari rferrari closed this Oct 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants