-
-
Notifications
You must be signed in to change notification settings - Fork 22
Closed
Description
Bug Report
1.14.0
crashes and leaks repository secrets.
Q | A |
---|---|
Version(s) | 1.14.0 |
Summary
The 1.14.0
image has now been dropped, as a security precaution.
Two problems arise:
- in case of
git
operations failing, we get a crash with un-masked secrets (really bad, although not exploitable, luckily) - because
git
added "security" around operating on repositories owned by other users, we have crashing release processes, like https://github.com/scoutapp/scout-apm-php-ext/runs/7518545888?check_suite_focus=true
Metadata
Metadata
Assignees
Labels
BugSomething isn't workingSomething isn't working