Skip to content

Accessibility scanner action flags GitHub's own /pages/auth infrastructure page (Actions) #210

Description

@GrimaceDoesA11y

When running the scanner action on a private GitHub Pages site, the scanner flags an axe page-has-heading-one violation on the URL /pages/auth. This page is GitHub's own built-in authentication page (the login gate for private GitHub Pages sites), not a page a user can author or control.

The scanned element contains attributes like data-turbo-loaded, data-color-mode, data-a11y-animated-images, and js-focus-visible, which confirm it is GitHub's own UI, not user content. We cannot fix this violation because we do not own the page.

In our case, this triggered 30 duplicate pull requests in our repository (as we ran on a list of URLs), all attempting to create a pages/auth.html file that has no effect on the actual scanned page.

Request:

Please either

  • (1) fix the accessibility violation on GitHub's own /pages/auth page, or
  • (2) update the github/accessibility-scanner action to exclude GitHub-infrastructure URLs from its scan scope by default, or
  • document how to configure URL exclusions for these pages

The private repo with CoPilot's attempts to fix the issue:
https://github.com/mcdonalds-corp-new/ally/pull/84

URL of the workflow run:
https://github.com/mcdonalds-corp-new/ally/actions/runs/24263521708/job/70852992850

Error message:
Set issue Accessibility issue: Heading levels should only increase by one on /pages/auth (mcdonalds-corp-new/ally#25) state to closed Set issue Accessibility issue: Page should contain a level-one heading on /pages/auth (mcdonalds-corp-new/ally#26) state to closed

Workflow file and workflow run log attached.

gh-a11y-scanner.yml

logs_64167249977.zip

Activity

  1. abdulahmad307 commented on Apr 30, 2026

    @abdulahmad307
    Contributor

    Hi @GrimaceDoesA11y 👋, thanks for reporting this.

    So, looking at the workflow file you provided, the list of urls doesn't include pages/auth, which could mean that a redirect is happening from one of the actual urls to the auth page. If this is the case, the scanner will not know that this redirect is unintentional, and will scan the page that the playwright browser lands on (which would be pages/auth after the redirect is complete).

    To avoid this redirect (assuming that's the case), you can provide an auth_context input to the scanner in the workflow - see line 35 in the workflow file. This will make the browser think that the session is authenticated (or logged in), and will skip the redirect and land on the intended page url.

    Hope that helps. Let us know if you have more questions. Also, have a look through the docs on how to use the auth_context

  2. GrimaceDoesA11y commented on Apr 30, 2026

    @GrimaceDoesA11y
    Author

    @abdulahmad307 thank you for the clarification. I tried auth_context with my info but it still reports the same issue:

    1. https://github.com/mcdonalds-corp-new/ally/issues/103
    2. https://github.com/mcdonalds-corp-new/ally/issues/104

    I'm not sure if I'm doing this correctly, as I normally login via SSO to an enterprise account. This account is not that account.

  3. abdulahmad307 commented on May 11, 2026

    @abdulahmad307
    Contributor

    Hello again - sorry for the delay in responding.

    Gotcha 🤔 . It's going to be a bit difficult to help with debugging without being able to understand how auth works at your organization. We also use SSO, and we built a custom action* that will perform the necessary auth steps, and return the auth data to the workflow so we can pass it along to the scanner via auth_context. It sounds like you will need to do something similar.

    *We use playwright to navigate through our login steps and provide the right credentials to generate a valid session.

    also, I'm not able to access any of the issues/links you're sharing - they're probably private org links

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions