github / github/vscode-github-actions
false positive error on `secrets` context access in forks
- 主要言語
- TypeScript
- スター
- 660
- フォーク
- 213
- PR マージ指標
- 30日以内にマージされた PR はありません
説明
For a workflow that accesses secrets:
```yml
- name: "publish npm"
uses: "./.github/actions/publish-npm"
env:
NPM_TOKEN: "${{ secrets.NPM_TOKEN }}"
```
The extension is very helpful in checking if the secret `NPM_TOKEN` is actually defined or not.
However, it only checks secrets defined in the same repository (I suspect `origin` remote), and reports a false-positive error if it was defined in `upstream`, and `origin` is actually pointing to a fork:
> Context access might be invalid: NPM_TOKEN
**Expected behavior**
All remotes to be checked for secrets, not just `origin`, and the error is no longer reported.
**Screenshots**
**Extension Version**
`v0.26.3`
コントリビューションガイド
調査の方向性
Start by locating the extension's validation of GitHub Actions secrets and how it determines the repository or remotes to inspect. Reproduce the fork-and-upstream scenario described in the issue, then verify that a secret defined upstream no longer produces a false-positive context-access error.
索引モデルが issue の本文から書いたものです。
評価
- 技術スタック
- github-actions, typescript, vscode
- 領域
- ci-cd, devtools
- issue の種類
- バグ
- 難易度
- 3/5
- 見積もり時間
- 1〜2日
- 活発さ
- 停滞
- 明瞭さ
- おおむね明確
- 初心者へのやさしさ
- 45/100