Secrets not detected in an action workflow #54901
Replies: 3 comments
-
That you get stars in the log is intentional, GitHub masks secrets in the log to prevent them from leaking. You can work around it, but it's hard to do safely: If you just trick the masking process, everyone with access to the logs/artifacts can see your secrets. If your repository is public, literally anyone can see your logs and artifacts. A safe option would be to upload a public key (keep the matching private one to yourself!), encrypt the data using that key, and log the result or upload it as an artifact. Decrypt locally with the private key, and you have your secrets. Easier, but unsafe options are:
|
Beta Was this translation helpful? Give feedback.
-
I'm having nearly the same problem, my secret is not given to the maven process: gpg: no default secret key: No secret key The weird is that it worked last week without problems. |
Beta Was this translation helpful? Give feedback.
-
🕒 Discussion Activity Reminder 🕒 This Discussion has been labeled as dormant by an automated system for having no activity in the last 60 days. Please consider one the following actions: 1️⃣ Close as Out of Date: If the topic is no longer relevant, close the Discussion as 2️⃣ Provide More Information: Share additional details or context — or let the community know if you've found a solution on your own. 3️⃣ Mark a Reply as Answer: If your question has been answered by a reply, mark the most helpful reply as the solution. Note: This dormant notification will only apply to Discussions with the Thank you for helping bring this Discussion to a resolution! 💬 |
Beta Was this translation helpful? Give feedback.
-
Select Topic Area
Question
Body
I have an organization secrets configured in my repo but when runs my workflow and then I take a look in my *.yml file to see "my secrets" (I must be able tu see **** instead secret) using an echo command but I don't see nothing.
I made another tests in another repos and i'm able to see "****"
¿do you know what could be?
Beta Was this translation helpful? Give feedback.
All reactions