apache/kafka · error · ValueError

GITHUB_TOKEN is not set in the environment

Error message

GITHUB_TOKEN is not set in the environment

What it means

committer-tools/refresh_collaborators.py reads GITHUB_TOKEN from the environment at import time (os.getenv). get_github_client refuses to construct a PyGithub client when the token is missing and raises ValueError, because every GitHub API call (listing committers, reading .asf.yaml, opening PRs) requires authentication with sufficient rate limit.

Solutions

  1. Export a classic PAT or fine-grained token: `export GITHUB_TOKEN=ghp_...` then re-run.
  2. In CI, add GITHUB_TOKEN as a secret/env var on the job.
  3. Put `export GITHUB_TOKEN=...` in the project's local .env (sourced before running) - never commit the token.
  4. Verify the token has repo scope for apache/kafka and apache/kafka-site.

Example fix

# before
$ python3 committer-tools/refresh_collaborators.py
ERROR: GITHUB_TOKEN is not set in the environment -> ValueError

# after
$ export GITHUB_TOKEN=ghp_xxxxxxxxxxxxxxxx
$ python3 committer-tools/refresh_collaborators.py
Defensive patterns

Strategy: validation

Validate before calling

import os
if not os.getenv("GITHUB_TOKEN"):
    raise SystemExit("Set GITHUB_TOKEN before running: export GITHUB_TOKEN=ghp_...")

Type guard

null

Try / catch

try:
    client = get_github_client()
except ValueError as e:
    print(f"Auth error: {e}", file=sys.stderr)
    sys.exit(2)

Prevention

When it happens

Trigger: Running `python3 committer-tools/refresh_collaborators.py` in a shell or CI job where GITHUB_TOKEN is not exported, or is exported as an empty string.

Common situations: New contributor running the tool without reading docs; CI runner missing the secret; token name typo (e.g. GH_TOKEN instead of GITHUB_TOKEN); running under a different user/shell where the export was not persisted.

Related errors


AI-assisted analysis of apache/kafka@996fb4585a (2026-08-11). Data as JSON: /api/errors/76a54551e9fe894d. Report an issue: GitHub.

Appendix: source

Thrown at committer-tools/refresh_collaborators.py:58

logging.basicConfig(
    format="%(asctime)s %(levelname)s %(message)s",
    level=logging.INFO,
)

GITHUB_TOKEN: str = os.getenv("GITHUB_TOKEN")
REPO_KAFKA_SITE: str = "apache/kafka-site"
REPO_KAFKA: str = "apache/kafka"
ASF_YAML_PATH: str = "../.asf.yaml"
TOP_N_CONTRIBUTORS: int = 10


def get_github_client() -> Github:
    """
    Initialize GitHub client with token.
    """
    if not GITHUB_TOKEN:
        logging.error("GITHUB_TOKEN is not set in the environment")
        raise ValueError("GITHUB_TOKEN is not set in the environment")

    logging.info("Successfully initialized GitHub client")
    return Github(GITHUB_TOKEN)


def get_committers_list(repo: Repository) -> List[str]:
    """
    Fetch the committers from the given repository.
    """
    logging.info(f"Fetching committers from the repository {REPO_KAFKA_SITE}")
    committers_file: ContentFile = repo.get_contents("committers.html")
    content: bytes = committers_file.decoded_content
    soup: BeautifulSoup = BeautifulSoup(content, "html.parser")

    committers = [login.text for login in soup.find_all("div", class_="github_login")]
    logging.info(f"Found {len(committers)} committers")
    return committers

View on GitHub (pinned to 996fb4585a)