docs icon indicating copy to clipboard operation
docs copied to clipboard

Documentation about secrets for step condition could elaborate on implications of the approach

Open m-kuhn opened this issue 2 years ago • 10 comments

I think this would deserve a hint on the implication that the secret is leaked to every step within the job, regardless if it's required for a certain step or not (hence violating the principle of least privilege).

Originally posted by @m-kuhn in https://github.com/github/docs/issues/12722#issuecomment-1172714298

m-kuhn avatar Jul 08 '22 22:07 m-kuhn

Thanks for opening this issue. A GitHub docs team member should be by to give feedback soon. In the meantime, please check out the contributing guidelines.

welcome[bot] avatar Jul 08 '22 22:07 welcome[bot]

@m-kuhn Thanks for opening a new issue for this. I'll get it triaged for review! ⚡

cmwilson21 avatar Jul 11 '22 18:07 cmwilson21

Thanks for opening an issue! We've triaged this issue for technical review by a subject matter expert :eyes:

github-actions[bot] avatar Jul 12 '22 04:07 github-actions[bot]

Thanks also

Benson665 avatar Jul 13 '22 01:07 Benson665

This is a gentle bump for the docs team that this issue is waiting for technical review.

github-actions[bot] avatar Jul 20 '22 20:07 github-actions[bot]

This is a gentle bump for the docs team that this issue is waiting for technical review.

github-actions[bot] avatar Jul 28 '22 20:07 github-actions[bot]

This is a gentle bump for the docs team that this issue is waiting for technical review.

github-actions[bot] avatar Aug 05 '22 20:08 github-actions[bot]

This is a gentle bump for the docs team that this issue is waiting for technical review.

github-actions[bot] avatar Sep 05 '22 20:09 github-actions[bot]

This is a gentle bump for the docs team that this issue is waiting for technical review.

github-actions[bot] avatar Oct 04 '22 20:10 github-actions[bot]

This is a gentle bump for the docs team that this issue is waiting for technical review.

github-actions[bot] avatar Jan 03 '23 16:01 github-actions[bot]

This is a gentle bump for the docs team that this issue is waiting for technical review.

github-actions[bot] avatar Feb 01 '23 16:02 github-actions[bot]

This is a gentle bump for the docs team that this issue is waiting for technical review.

github-actions[bot] avatar Mar 02 '23 16:03 github-actions[bot]

This is a gentle bump for the docs team that this issue is waiting for technical review.

github-actions[bot] avatar Mar 31 '23 16:03 github-actions[bot]