Skip to content

Commit 865c1c5

Browse files
committed
Fix CI's verible download hitting GitHub's unauthenticated rate limit
The lint job resolved verible's release asset URL with a bare curl call against api.github.com, which shares a 60 req/hr limit across every job on the runner's IP range -- easy to exceed, and it started returning 403 instead of the release JSON. Switched to `gh release download`, authenticated with the job's own token, which gets a much higher per-job limit instead of a shared per-IP one.
1 parent 6a1d668 commit 865c1c5

1 file changed

Lines changed: 8 additions & 6 deletions

File tree

‎.github/workflows/ci.yml‎

Lines changed: 8 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -15,13 +15,15 @@ jobs:
1515
- name: Download verible
1616
# Verible's release asset filenames embed the version tag (e.g.
1717
# verible-v0.0-4145-g7bd8603b-linux-static-x86_64.tar.gz), so there's
18-
# no stable /latest/download/<name> URL to hardcode -- resolve the
19-
# actual asset URL from the API instead.
18+
# no stable /latest/download/<name> URL to hardcode -- resolve it via
19+
# `gh release download` instead of an unauthenticated curl hit on the
20+
# GitHub API, which shares a 60 req/hr rate limit across every job on
21+
# the runner's IP range and started 403ing. `gh` is preinstalled on
22+
# GitHub-hosted runners and authenticates with the job's own token.
23+
env:
24+
GH_TOKEN: ${{ github.token }}
2025
run: |
21-
url=$(curl -fsSL https://api.github.com/repos/chipsalliance/verible/releases/latest \
22-
| grep -o '"browser_download_url": *"[^"]*linux-static-x86_64[^"]*"' \
23-
| head -1 | sed -E 's/.*"(https[^"]+)"/\1/')
24-
curl -fsSL -o verible.tar.gz "$url"
26+
gh release download --repo chipsalliance/verible --pattern '*linux-static-x86_64*' --output verible.tar.gz
2527
mkdir -p verible && tar xzf verible.tar.gz -C verible --strip-components=1
2628
echo "$PWD/verible/bin" >> "$GITHUB_PATH"
2729
- name: Check formatting

0 commit comments

Comments
 (0)