github / github/vscode-github-actions

Feature request: Sync repo/org secrets to local .env for local development

オープン
#598 コメント 0 件 リアクション 1 件 担当者 0 名 GitHub で見る
enhancement
主要言語
TypeScript
スター
660
フォーク
213
PR マージ指標
30日以内にマージされた PR はありません

説明

## Problem

Developers working locally must manually copy secrets into `.env`. Error-prone. Painful at scale. Drift between CI and local dev.

Extension already lists secret names in "Secrets" and "Variables" views. Cannot bridge to local env.

## Proposed solution

Add command: **"GitHub Actions: Pull Secrets to .env"**

1. Authenticate via existing GitHub login
2. Fetch secret names for current repo + environments (same scope as Secrets view)
3. Preview available secrets (names only)
4. On confirm, fetch decrypted values (workflow-execution approach or new API endpoint)
5. Write `.env` at workspace root (configurable)

## Alternatives

| Option | Gap |
|---|---|
| Manual `.env` | Current flow — time-consuming, drift-prone |
| `act` + secret file | Need values already local. No help sourcing |
| GitHub Codespaces | Auto-injects. But only for Codespaces, not local |
| `gh` extension | Separate tool, extra auth context |

## Constraints

- GitHub API does not expose secret plaintext (encrypted at rest by design)
- Needs either: new API endpoint OR one-time workflow that echoes base64-encoded secret values
- Solution parallel to how Codespaces injects secrets into the environment

## Prior art

- **Codespaces**: already auto-injects secrets into dev environment. This request brings parity to local dev.
- **#222** (500+ reactions): clear demand for improved secrets UX in extension

## Success criteria

- Open local repo in VS Code → run "Pull Secrets to .env"
- GitHub auth (once) → see available secrets by scope
- Confirm → `.env` written at workspace root
- `.env` auto-`.gitignore`-d if absent

コントリビューションガイド

コントリビューションガイドを開く

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。