github / github/vscode-github-actions
false positive error on `secrets` context access in forks
- Ngôn ngữ chính
- TypeScript
- Star
- 660
- Fork
- 213
- Chỉ số merge pull request
- Không có pull request nào được merge trong 30 ngày
Mô tả
For a workflow that accesses secrets:
```yml
- name: "publish npm"
uses: "./.github/actions/publish-npm"
env:
NPM_TOKEN: "${{ secrets.NPM_TOKEN }}"
```
The extension is very helpful in checking if the secret `NPM_TOKEN` is actually defined or not.
However, it only checks secrets defined in the same repository (I suspect `origin` remote), and reports a false-positive error if it was defined in `upstream`, and `origin` is actually pointing to a fork:
> Context access might be invalid: NPM_TOKEN
**Expected behavior**
All remotes to be checked for secrets, not just `origin`, and the error is no longer reported.
**Screenshots**
**Extension Version**
`v0.26.3`
Hướng dẫn đóng góp
Hướng nghiên cứu
Bắt đầu bằng cách xác định phần extension xác thực các secret của GitHub Actions và cách nó xác định repository hoặc các remote cần kiểm tra. Tái hiện kịch bản fork và upstream được mô tả trong issue, sau đó xác minh rằng một secret được định nghĩa ở upstream không còn tạo ra lỗi truy cập context dương tính giả.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Đánh giá
- Công nghệ
- github-actions, typescript, vscode
- Lĩnh vực
- ci-cd, devtools
- Loại issue
- Lỗi
- Độ khó
- 3/5
- Thời gian dự kiến
- 1-2 ngày
- Mức độ hoạt động
- Đình trệ
- Độ rõ ràng
- Khá rõ ràng
- Mức phù hợp với người mới
- 45/100