Both jobs fail on the Gitea mirror for reasons no secret or input changes. hassfest is a Docker-container action that bind-mounts $GITHUB_WORKSPACE. The Gitea runner runs the job inside a container against a separate docker-in-docker daemon, so the path resolves on the daemon's filesystem, not the job's; docker creates an empty directory and mounts that, and hassfest then accurately reports that it found no integrations in the empty tree it was given. It takes no token, so credentials were never the issue. HACS asks the github.com API about github.repository, which on Gitea is flan/ha-freshharvest -- a slug that exists only on Gitea. That is the 401. The action has no input to point the lookup at the sudolulo mirror. The same commit that fails here passes on github.com/sudolulo/ha-freshharvest, which mirrors every push, so the validation still happens -- it just happens where it is capable of running. The guard is "not Gitea" rather than "is GitHub" so an unexpected server_url runs the checks instead of dropping them. pytest is untouched and still gates every push on both forges.