diff --git a/action.yml b/action.yml index ecada4b..dfeddd2 100644 --- a/action.yml +++ b/action.yml @@ -3,7 +3,7 @@ description: 'Clones a repository via SSH on a custom port.' inputs: ssh-key: - description: 'Private SSH Key' + description: 'Private SSH Key, base64-encoded on a single line (e.g. `base64 -w0 id_ed25519`). A raw PEM key still works but is not masked in the logs.' required: true ref: description: 'Branch, tag, or commit SHA to checkout' @@ -38,8 +38,13 @@ runs: mkdir -p ~/.ssh chmod 700 ~/.ssh - # 2. Write the private key to a file as-is - printf '%s\n' "$SSH_KEY" > ~/.ssh/gitea_key + # 2. Write the private key to a file + # The key is expected base64-encoded so it's a single-line secret the runner can mask; + # raw multi-line PEM keys are still accepted for backwards compatibility. + case "$SSH_KEY" in + *"-----BEGIN"*) printf '%s\n' "$SSH_KEY" > ~/.ssh/gitea_key ;; + *) printf '%s' "$SSH_KEY" | tr -d '[:space:]' | base64 -d > ~/.ssh/gitea_key ;; + esac chmod 600 ~/.ssh/gitea_key # 3. Configure SSH for the custom port and bypass host key prompt