Skip to content

Commit ea26899

Browse files
committed
Moved secrets to env vars to avoid expansion in run blocks
1 parent 8fd509d commit ea26899

5 files changed

+27
-13
lines changed

.github/workflows/sync-changes-to-gitlab.yml

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -22,6 +22,8 @@ jobs:
2222
fetch-depth: 0
2323

2424
- name: Push changes to gitlab.com/kudoai/chatgpt-js
25+
env:
26+
GITLAB_SYNC_PAT: ${{ secrets.GITLAB_SYNC_PAT }}
2527
run: |
2628
git push --force -o ci.skip \
27-
https://oauth2:${{ secrets.GITLAB_SYNC_PAT }}@gitlab.com/kudoai/chatgpt-js.git main
29+
https://oauth2:[email protected]/kudoai/chatgpt-js.git main

.github/workflows/sync-chatgpt.js-changes-to-chrome-starter.yml

Lines changed: 6 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -52,14 +52,17 @@ jobs:
5252
echo "ESCAPED_MSG<<EOF" >> $GITHUB_ENV
5353
echo "$COMMIT_MSG" | sed 's/`/\`/g' >> $GITHUB_ENV
5454
echo "EOF" >> $GITHUB_ENV
55-
55+
5656
- name: Config committer
57+
env:
58+
GPG_PRIVATE_KEY: ${{ secrets.GPG_PRIVATE_KEY }}
59+
GPG_PRIVATE_ID: ${{ secrets.GPG_PRIVATE_ID }}
5760
run: |
58-
gpg --batch --import <(echo "${{ secrets.GPG_PRIVATE_KEY }}")
61+
gpg --batch --import <(echo "$GPG_PRIVATE_KEY")
5962
git config --global commit.gpgsign true
6063
git config --global user.name "kudo-sync-bot"
6164
git config --global user.email "[email protected]"
62-
git config --global user.signingkey "${{ secrets.GPG_PRIVATE_ID }}"
65+
git config --global user.signingkey "$GPG_PRIVATE_ID"
6366
6467
- name: Push changes to KudoAI/chatgpt.js
6568
run: |

.github/workflows/sync-chrome-starter-changes.yml

Lines changed: 6 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -42,14 +42,17 @@ jobs:
4242
echo "ESCAPED_MSG<<EOF" >> $GITHUB_ENV
4343
echo "$COMMIT_MSG" | sed 's/`/\`/g' >> $GITHUB_ENV
4444
echo "EOF" >> $GITHUB_ENV
45-
45+
4646
- name: Config committer
47+
env:
48+
GPG_PRIVATE_KEY: ${{ secrets.GPG_PRIVATE_KEY }}
49+
GPG_PRIVATE_ID: ${{ secrets.GPG_PRIVATE_ID }}
4750
run: |
48-
gpg --batch --import <(echo "${{ secrets.GPG_PRIVATE_KEY }}")
51+
gpg --batch --import <(echo "$GPG_PRIVATE_KEY")
4952
git config --global commit.gpgsign true
5053
git config --global user.name "kudo-sync-bot"
5154
git config --global user.email "[email protected]"
52-
git config --global user.signingkey "${{ secrets.GPG_PRIVATE_ID }}"
55+
git config --global user.signingkey "$GPG_PRIVATE_ID"
5356
5457
- name: Push changes to KudoAI/chatgpt.js-chrome-starter
5558
run: |

.github/workflows/sync-en-readme-changes.yml

Lines changed: 6 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -43,14 +43,17 @@ jobs:
4343
echo "ESCAPED_MSG<<EOF" >> $GITHUB_ENV
4444
echo "$COMMIT_MSG" | sed 's/`/\`/g' >> $GITHUB_ENV
4545
echo "EOF" >> $GITHUB_ENV
46-
46+
4747
- name: Config committer
48+
env:
49+
GPG_PRIVATE_KEY: ${{ secrets.GPG_PRIVATE_KEY }}
50+
GPG_PRIVATE_ID: ${{ secrets.GPG_PRIVATE_ID }}
4851
run: |
49-
gpg --batch --import <(echo "${{ secrets.GPG_PRIVATE_KEY }}")
52+
gpg --batch --import <(echo "$GPG_PRIVATE_KEY")
5053
git config --global commit.gpgsign true
5154
git config --global user.name "kudo-sync-bot"
5255
git config --global user.email "[email protected]"
53-
git config --global user.signingkey "${{ secrets.GPG_PRIVATE_ID }}"
56+
git config --global user.signingkey "$GPG_PRIVATE_ID"
5457
5558
- name: Push changes to KudoAI/chatgpt.js
5659
run: |

.github/workflows/sync-greasemonkey-starter-changes.yml

Lines changed: 6 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -42,14 +42,17 @@ jobs:
4242
echo "ESCAPED_MSG<<EOF" >> $GITHUB_ENV
4343
echo "$COMMIT_MSG" | sed 's/`/\`/g' >> $GITHUB_ENV
4444
echo "EOF" >> $GITHUB_ENV
45-
45+
4646
- name: Config committer
47+
env:
48+
GPG_PRIVATE_KEY: ${{ secrets.GPG_PRIVATE_KEY }}
49+
GPG_PRIVATE_ID: ${{ secrets.GPG_PRIVATE_ID }}
4750
run: |
48-
gpg --batch --import <(echo "${{ secrets.GPG_PRIVATE_KEY }}")
51+
gpg --batch --import <(echo "$GPG_PRIVATE_KEY")
4952
git config --global commit.gpgsign true
5053
git config --global user.name "kudo-sync-bot"
5154
git config --global user.email "[email protected]"
52-
git config --global user.signingkey "${{ secrets.GPG_PRIVATE_ID }}"
55+
git config --global user.signingkey "$GPG_PRIVATE_ID"
5356
5457
- name: Push changes to KudoAI/chatgpt.js-greasemonkey-starter
5558
run: |

0 commit comments

Comments
 (0)