Anonymous GitHub is capped at 60 requests/hour and cannot read private
repositories, so a machine credential usable by a free (non-enterprise)
account is needed to lift the request budget and reach private release
assets.
- Add internal/githubauth: a process-wide credential delivered via env/secret,
applied by default to every outbound GitHub request.
- Support two modes: a Personal Access Token sent as `Authorization: Bearer`,
and a GitHub App that mints a short-lived RS256 JWT (stdlib crypto, no new
dependency), exchanges it for a ~1h installation token, caches it, and
single-flights a refresh a few minutes before expiry.
- Inject the credential at the two GitHub call paths: the rpm github provider
(releases scan + ranged asset-header GETs) and the generic byte proxy
(private release-asset downloads for github.com hosts).
- Honor precedence: a remote's own username/password overrides the server
credential; no credential configured stays anonymous.
- Fail closed at startup on partial App configuration; never persist the
credential to the DB, return it from an API, or log it.
- Read GITHUB_TOKEN / GITHUB_APP_ID / GITHUB_APP_INSTALLATION_ID /
GITHUB_APP_PRIVATE_KEY[_PATH] via the existing getenv convention.
- Document PAT vs App setup, the free-account fine-grained PAT scopes
(Contents:read + Metadata:read), precedence, and the rate-limit implication.