dotnet / dotnet/sign

Pass secrets more secure way

Open
#613 2 comments 0 reactions 0 assignees View on GitHub
documentation Priority:3
Dominant language
C#
Stars
581
Forks
116
Avg merge
1d 2h
Merged PRs (30d)
8

Description

I assume signing happens on the CI pipeline, but many CI pipelines log CLI arguments and output for investigating issues. As a result, secrets may get logged into some storage without the user's knowledge by accident.
I'm wondering could we have another way of passing secrets other than CLI argument.
![image](https://user-images.githubusercontent.com/8766776/226701621-51ff19b9-c666-4ff6-a3a0-89f1fdd286e4.png)

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.