github / github/vscode-github-actions
Feature request: Sync repo/org secrets to local .env for local development
- Lenguaje dominante
- TypeScript
- Estrellas
- 660
- Forks
- 213
- Métricas de merge de PR
- Sin PR fusionados en 30 d
Descripción
## Problem
Developers working locally must manually copy secrets into `.env`. Error-prone. Painful at scale. Drift between CI and local dev.
Extension already lists secret names in "Secrets" and "Variables" views. Cannot bridge to local env.
## Proposed solution
Add command: **"GitHub Actions: Pull Secrets to .env"**
1. Authenticate via existing GitHub login
2. Fetch secret names for current repo + environments (same scope as Secrets view)
3. Preview available secrets (names only)
4. On confirm, fetch decrypted values (workflow-execution approach or new API endpoint)
5. Write `.env` at workspace root (configurable)
## Alternatives
| Option | Gap |
|---|---|
| Manual `.env` | Current flow — time-consuming, drift-prone |
| `act` + secret file | Need values already local. No help sourcing |
| GitHub Codespaces | Auto-injects. But only for Codespaces, not local |
| `gh` extension | Separate tool, extra auth context |
## Constraints
- GitHub API does not expose secret plaintext (encrypted at rest by design)
- Needs either: new API endpoint OR one-time workflow that echoes base64-encoded secret values
- Solution parallel to how Codespaces injects secrets into the environment
## Prior art
- **Codespaces**: already auto-injects secrets into dev environment. This request brings parity to local dev.
- **#222** (500+ reactions): clear demand for improved secrets UX in extension
## Success criteria
- Open local repo in VS Code → run "Pull Secrets to .env"
- GitHub auth (once) → see available secrets by scope
- Confirm → `.env` written at workspace root
- `.env` auto-`.gitignore`-d if absent
Guía de contribución
Línea de trabajo
No files or tests are named. Start by tracing the existing Secrets and Variables views and the GitHub login flow, then verify whether the proposed secret-value retrieval is supported safely. Done means the command previews scoped secret names, confirms before writing the workspace-root .env, and adds it to .gitignore when absent.
Escrito por el modelo de indexación a partir del texto del issue.
Evaluación
- Stack tecnológico
- github, github-actions, typescript, vscode
- Área
- authentication, devtools, security
- Tipo de issue
- Nueva funcionalidad
- Dificultad
- 5/5
- Tiempo estimado
- Más de una semana
- Estado de actividad
- Tranquilo
- Claridad
- Bastante claro
- Aptitud para principiantes
- 35/100