publish-winget.yml has failed on every stable release since v1.12.0: v1.12.0, v1.12.1, v1.12.2 and v1.13.0 (run 36000771103). The failing step is vedantmgoyal9/winget-releaser (komac):
0: EtienneLescot does not have the correct permissions to execute `CreateRef`
1: failed to create branch OpenScreen.OpenScreen-1.13.0-5EF7C8FAFFC34DCD89665971980B4936
What is already in place (so this is no longer the "not configured" case #148 was about):
WINGET_IDENTIFIER = OpenScreen.OpenScreen, and WINGET_ACC_TOKEN is set; the run gets past the configuration check.
- A fork exists under the org:
getopenscreen/winget-pkgs. There is also a personal fork, EtienneLescot/winget-pkgs, last pushed 2026-08-11.
- The package exists upstream, so the "first manifest must be manual" prerequisite is met.
microsoft/winget-pkgs has 1.9.2, 1.9.6, 1.10.0 (submitted by hand), plus 1.11.0 and 1.12.2 (pushed by the community bot damn-good-b0t, not by us). 1.12.0, 1.12.1 and 1.13.0 are missing. 1.10.0 also needed a follow-up InstallerSha256 fix (#423711 upstream).
Likely cause, to confirm: the action's fork-user defaults to the repository owner (getopenscreen), so komac tries to create a branch in getopenscreen/winget-pkgs with a token that belongs to EtienneLescot. A CreateRef denial with a valid token points at one of three things:
- the token's scopes, since it must be a classic PAT with
public_repo;
- an org policy restricting classic PATs on
getopenscreen;
fork-user pointing at a fork the token cannot write to.
Also stale: technical-documentation/engineering/release-and-secrets.md still says WINGET_ACC_TOKEN is absent. The workflow's warning text still lists prerequisites that are now met.
Expected: a stable release lands in microsoft/winget-pkgs through our workflow, and a failure names the actual missing permission instead of a generic komac error.
publish-winget.ymlhas failed on every stable release since v1.12.0: v1.12.0, v1.12.1, v1.12.2 and v1.13.0 (run 36000771103). The failing step isvedantmgoyal9/winget-releaser(komac):What is already in place (so this is no longer the "not configured" case #148 was about):
WINGET_IDENTIFIER=OpenScreen.OpenScreen, andWINGET_ACC_TOKENis set; the run gets past the configuration check.getopenscreen/winget-pkgs. There is also a personal fork,EtienneLescot/winget-pkgs, last pushed 2026-08-11.microsoft/winget-pkgshas 1.9.2, 1.9.6, 1.10.0 (submitted by hand), plus 1.11.0 and 1.12.2 (pushed by the community botdamn-good-b0t, not by us). 1.12.0, 1.12.1 and 1.13.0 are missing. 1.10.0 also needed a follow-upInstallerSha256fix (#423711 upstream).Likely cause, to confirm: the action's
fork-userdefaults to the repository owner (getopenscreen), so komac tries to create a branch ingetopenscreen/winget-pkgswith a token that belongs toEtienneLescot. ACreateRefdenial with a valid token points at one of three things:public_repo;getopenscreen;fork-userpointing at a fork the token cannot write to.Also stale:
technical-documentation/engineering/release-and-secrets.mdstill saysWINGET_ACC_TOKENis absent. The workflow's warning text still lists prerequisites that are now met.Expected: a stable release lands in
microsoft/winget-pkgsthrough our workflow, and a failure names the actual missing permission instead of a generic komac error.