Repository navigation
fix(release-image): stop printing decoded build secrets to job logs (PT-554) - #78
Merged
Merged
Conversation
…PT-554)
The build job converted build_params_gh_secret_keys into KEY=VALUE lines and
ran `cat .env`, so each value was printed in plaintext (the runner only masks
the original JSON blob, not the reformatted values).
- Remove the `cat .env` and the other echo of derived values.
- Register ::add-mask:: for every value, per line and %-escaped, before any
value is written to GITHUB_ENV, .env or secrets.json.
- Pass the secret JSON through env: instead of interpolating ${{ }} into the
run script.
- Write GITHUB_ENV entries with a random heredoc delimiter so multi-line values
cannot inject extra variables; reject malformed key names.
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HjV5itQyr9Le6ouhChLg1c
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01HjV5itQyr9Le6ouhChLg1c
…jq stderr Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01HjV5itQyr9Le6ouhChLg1c
MaximusHaximus
approved these changes
Oct 7, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Requested by Will Button · Slack thread
Description
Before: the
buildjob ingcp_pipeline_release_image.yamlconvertedbuild_params_gh_secret_keysintoKEY=VALUElines and then ranecho ".env contents:" && cat .env. The runner only masks the original JSON blob, not the reformatted values, so every build secret was printed in plaintext in the job log (public for public caller repos such asproof-generation-apiand this repo). The values were also appended toGITHUB_ENV, and the secret was interpolated straight into therun:script via${{ }}.After: the decoded values are never printed, every value is masked before it is written anywhere, and the secret JSON reaches the script through
env:instead of template interpolation.How: the two old steps ("Set up secrets" and "Parse secrets and set environment variables") are merged into one step, "Set up secrets and environment variables".
BUILD_PARAMS_SECRETSis passed viaenv:, so the JSON is never parsed as shell.::add-mask::for each value, one call per line (a mask only matches a single line), with%escaped as%25because the runner %-decodes workflow-command data. This runs before anything is written toGITHUB_ENV,.envorsecrets.json.GITHUB_ENV,.envandsecrets.json.GITHUB_ENVentries use a random heredoc delimiter, so a multi-line value can no longer inject extra variables. Malformed key names (empty, or containing=,<<, or a newline) fail the step.cat .envis removed. jq's stderr is discarded because its errors can quote fragments of the input.workflow_callinputs, outputs and secrets are unchanged..envkeeps its existing format (KEY=VALUE, each record CR-terminated),secrets.jsonis still written, and values are still exported to later steps viaGITHUB_ENV.echo "..."unescaped\", so the secret may be stored with backslash-escaped quotes. If it does not parse as JSON as-is, the step retries once with\"unescaped before failing.Fixes PT-554
Type of change
Checklist:
lintto ensure the code style is validAdditional context
Human follow-up: rotate exposed secrets. Any build secrets that were printed in historical logs of caller repos that pass
build_params_gh_secret_keys(includingproof-generation-apiandpipelines) should be treated as exposed and rotated. This PR stops new leaks but does not scrub old logs.Validation. The step script was extracted and run locally against a stub
GITHUB_ENVwith plain, multi-line, CRLF,%0A,$(...)/backtick, non-string, empty and trailing-newline values. All masks were emitted before any write, no value was echoed, nothing was executed, andGITHUB_ENVand.envwere correct. Invalid JSON, a bad key, an empty secret and the legacy\"-escaped form were also checked.shellcheckis clean, YAML parses, andzizmordrops from 20 to 18 findings with none left in this step. The remaining findings (artipacked, and template-injection in thepreparetag step and themergejob) are unrelated and out of scope. This has not been exercised on a real GitHub runner.Not done (follow-up). Preferring
docker/build-push-actionsecrets:(BuildKit secret mounts) overGITHUB_ENV/.envwould also keep values out of later steps, but it requires caller Dockerfiles to move toRUN --mount=type=secret, so it is left out here.ecs_deploy_docker_taskdef.yamlandnpm_build_deploy_default.yamlhave the sameecho "${{ secrets.build_params_gh_secret_keys }}"interpolation pattern and are untouched.🤖 Generated with Claude Code
https://claude.ai/code/session_01HjV5itQyr9Le6ouhChLg1c
Generated by Claude Code