Add selective retries for STS token exchange (#532)
## Summary The workload identity flow retries GitHub OIDC token retrieval, but `@actions/http-client` does not retry the POST to Google Security Token Service. A transient connection reset or socket timeout therefore ends authentication on the first failed exchange. This change adds four bounded STS attempts with 100, 200, and 400 ms backoffs. Retries are limited to connection failures and HTTP 408, 429, 500, 502, 503, and 504 responses. HTTP 400, 401, 403, empty responses, and unknown errors fail without retrying. Attempt diagnostics contain only the operation, STS hostname, status or classified error, and attempt count. The existing STS request and computed-audience debug messages were removed so these diagnostics do not include the OIDC assertion, returned access token, headers, credential data, service account, or workload identity provider resource. Mocked tests cover each retryable HTTP status, connection errors, the uncoded `@actions/http-client` socket timeout, permanent HTTP failures, the four-attempt limit, and diagnostic redaction.
B
Brian Lalor committed
12060449e87204eca501a11f2f7f1483024afff0
Parent: cd3439a
Committed by GitHub <noreply@github.com>
on 7/29/2026, 8:22:35 PM