AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

Vercel Deployment Authorization Script Fails Due To Unauthenticated GitHub API Calls And Missing Reliability Features

The script calls GitHub Status API without authentication, causing rate limit errors and failure on private repos. It also lacks timeout, retry, configurable repo, safe null handling, and correct exit codes, making CI deployments flaky.

highConfidence 85%Node.js

Origin Analysis

The script performs unauthenticated GitHub API requests to fetch commit statuses, uses a hardcoded supabase/supabase repo, has no network timeout or retry logic, assumes target_url is always non-null, and always exits 0 even on failure.
1. Set only HEAD_COMMIT_SHA and VERCEL_TOKEN in CI. 2. Run the Vercel authorization script. 3. Script calls https://api.github.com/repos/supabase/supabase/statuses/{sha} without Authorization header. 4. GitHub API returns 403 rate limit exceeded or 404 for private repo. 5. Script logs error but exits 0, deployment authorization fails silently.

Fixing Code Block

Edge Case Audit

Requires GITHUB_TOKEN to be available as a secret; if missing, the script will fail fast. Retry logic may increase job duration under persistent failures. The timeout could abort slow GitHub responses; adjust timeoutMs if large statuses. Rolling back to the original script is safe only if GITHUB_TOKEN is unset. Ensure Vercel API endpoint remains compatible if further changes are made.

Ecosystem Topology