github / github/vscode-github-actions

false positive error on `secrets` context access in forks

オープン
#375 コメント 3 件 リアクション 1 件 担当者 0 名 GitHub で見る
bug
主要言語
TypeScript
スター
660
フォーク
213
PR マージ指標
30日以内にマージされた PR はありません

説明

For a workflow that accesses secrets:

```yml
- name: "publish npm"
uses: "./.github/actions/publish-npm"
env:
NPM_TOKEN: "${{ secrets.NPM_TOKEN }}"
```

The extension is very helpful in checking if the secret `NPM_TOKEN` is actually defined or not.
However, it only checks secrets defined in the same repository (I suspect `origin` remote), and reports a false-positive error if it was defined in `upstream`, and `origin` is actually pointing to a fork:

> Context access might be invalid: NPM_TOKEN

**Expected behavior**

All remotes to be checked for secrets, not just `origin`, and the error is no longer reported.

**Screenshots**

image

**Extension Version**
`v0.26.3`

コントリビューションガイド

コントリビューションガイドを開く

調査の方向性

Start by locating the extension's validation of GitHub Actions secrets and how it determines the repository or remotes to inspect. Reproduce the fork-and-upstream scenario described in the issue, then verify that a secret defined upstream no longer produces a false-positive context-access error.

索引モデルが issue の本文から書いたものです。

評価

技術スタック
github-actions, typescript, vscode
領域
ci-cd, devtools
issue の種類
バグ
難易度
3/5
見積もり時間
1〜2日
活発さ
停滞
明瞭さ
おおむね明確
初心者へのやさしさ
45/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。