-
Notifications
You must be signed in to change notification settings - Fork 1k
Open
Description
Currently CodeQL is informing us about an issue in the generated wofklows:
Which makes sense, all the secrets are passed to the runners. That could potentially lead to unintentionally leaking secrets, especially organization or enterprise secrets are easily missed and should most likely not be passed to the action runners.
This PR proposes a way to be able to specify which secrets are to be passed to the action runners. It is fully backwards compatible, as not specifying the secrets in .upptimerc.yml provides the current behavior of passing all secrets.
Please have a look and let me know what you think.
Thanks in advance!
Metadata
Metadata
Assignees
Labels
No labels