You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Since the COMPOSE_VARS is base64 encoded before being stored as a secret, only the base64 encoded value will be protected from leakage by GH actions runners.
Once the value is unwrapped, GH runners will no longer match the secret hash and if the value makes it to some output, the secret values will leak into the runner logs.
The text was updated successfully, but these errors were encountered:
For external contributions this secret is not allowed and will exit the workflow. However there is still the possibility for internal contributors to accidentally leak this value and as such it should be deprecated.
Since the
COMPOSE_VARS
is base64 encoded before being stored as a secret, only the base64 encoded value will be protected from leakage by GH actions runners.Once the value is unwrapped, GH runners will no longer match the secret hash and if the value makes it to some output, the secret values will leak into the runner logs.
The text was updated successfully, but these errors were encountered: