fix(odd-status): keep the job token out of the checkout and say what --secret-env-vars does - #49
Merged
Merged
Conversation
…--secret-env-vars does Closes #43 Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
persist-credentials: falseon thetestsjob's checkout inci.ymland on the four README example workflows; the persisted job token is named in every "What this grants" section (nothing in these actions uses git with the token;release.ymlkeeps the default, its tag push needs it).scripts/run-copilot.sh,odd-status/README.md,setup-copilot/README.mdand thetokeninput description say what--secret-env-varsdoes, as the CLI's help states it: the value kept out of the environment of the shells and MCP servers the run opens and redacted from the output - a filter, not a boundary, since the CLI process holds the token and a same-user shell can read a process's environment; a user token passed astokenis exposed the same way.ci.ymlstates next tocopilot-requests: writewhy a fork'spull_requestrun does not get that scope (GitHub's documentation for a public repository; not observed on a fork run) and what the fork-approval policy adds; the smoke stays inci.yml.Why
Closes #43. The flag's help text, the local observation with a placeholder value, the documentation basis for the fork case and the amended choices are recorded on the issue.
How to test
actionlint 1.7.12, shellcheck, ruff and pytest (179 passed) locally; the
testsjob proves the checkout without credentials still installs the package (the resolve step reads the public oddyssey repository anonymously).Review
Review subagent: green after one round (the
tokendescription inaction.ymlstill said "never receive it"; five minors, all fixed). Security review: no findings.🤖 Generated with Claude Code