From 4b9b56ff8ddc7d56972777ecfe55e3db90bd036a Mon Sep 17 00:00:00 2001 From: Miley Hollenberg Date: Mon, 28 Sep 2026 14:15:44 +0200 Subject: [PATCH] Accept the SSH private key base64-encoded Multi-line secrets aren't masked by the runner, so a raw PEM key passed as ssh-key can end up in plain text in the step's env block in the log. Accept a single-line base64-encoded key instead, which is masked like any other secret. Raw PEM keys still work for backwards compatibility. Co-Authored-By: Claude Opus 5.5 --- action.yml | 11 ++++++++--- 1 file changed, 8 insertions(+), 3 deletions(-) diff --git a/action.yml b/action.yml index ecada4b..dfeddd2 100644 --- a/action.yml +++ b/action.yml @@ -3,7 +3,7 @@ description: 'Clones a repository via SSH on a custom port.' inputs: ssh-key: - description: 'Private SSH Key' + description: 'Private SSH Key, base64-encoded on a single line (e.g. `base64 -w0 id_ed25519`). A raw PEM key still works but is not masked in the logs.' required: true ref: description: 'Branch, tag, or commit SHA to checkout' @@ -38,8 +38,13 @@ runs: mkdir -p ~/.ssh chmod 700 ~/.ssh - # 2. Write the private key to a file as-is - printf '%s\n' "$SSH_KEY" > ~/.ssh/gitea_key + # 2. Write the private key to a file + # The key is expected base64-encoded so it's a single-line secret the runner can mask; + # raw multi-line PEM keys are still accepted for backwards compatibility. + case "$SSH_KEY" in + *"-----BEGIN"*) printf '%s\n' "$SSH_KEY" > ~/.ssh/gitea_key ;; + *) printf '%s' "$SSH_KEY" | tr -d '[:space:]' | base64 -d > ~/.ssh/gitea_key ;; + esac chmod 600 ~/.ssh/gitea_key # 3. Configure SSH for the custom port and bypass host key prompt