Skip to content

git broken on latest 1.14.0 image #198

@Ocramius

Description

@Ocramius

Bug Report

1.14.0 crashes and leaks repository secrets.

Q A
Version(s) 1.14.0

Summary

The 1.14.0 image has now been dropped, as a security precaution.

Two problems arise:

  1. in case of git operations failing, we get a crash with un-masked secrets (really bad, although not exploitable, luckily)
  2. because git added "security" around operating on repositories owned by other users, we have crashing release processes, like https://github.com/scoutapp/scout-apm-php-ext/runs/7518545888?check_suite_focus=true

Related: laminas/laminas-continuous-integration-action#99

Metadata

Metadata

Assignees

Labels

BugSomething isn't working

Type

No type

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions