Skip to content

Allow configuring which secrets are passed #1118

@4c0n

Description

@4c0n

Currently CodeQL is informing us about an issue in the generated wofklows:

Image

Which makes sense, all the secrets are passed to the runners. That could potentially lead to unintentionally leaking secrets, especially organization or enterprise secrets are easily missed and should most likely not be passed to the action runners.

This PR proposes a way to be able to specify which secrets are to be passed to the action runners. It is fully backwards compatible, as not specifying the secrets in .upptimerc.yml provides the current behavior of passing all secrets.

Please have a look and let me know what you think.
Thanks in advance!

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions