From 95bd0045344718a091fcb000698c75f5d1a75f08 Mon Sep 17 00:00:00 2001 From: Miley Hollenberg Date: Mon, 28 Sep 2026 13:48:59 +0200 Subject: [PATCH] Accept the SSH private key base64-encoded Multi-line secrets aren't masked by the runner, so a raw PEM key passed as private_key ends up in plain text in the step's env block in the log. Accept a single-line base64-encoded key instead, which is masked like any other secret. Raw PEM keys still work for backwards compatibility. Co-Authored-By: Claude Opus 5.5 --- action.yml | 9 +++++++-- 1 file changed, 7 insertions(+), 2 deletions(-) diff --git a/action.yml b/action.yml index 2fc7b77..f0a0933 100644 --- a/action.yml +++ b/action.yml @@ -3,7 +3,7 @@ description: 'Executes a shell command/script on a remote server via SSH on a cu inputs: private_key: - description: 'Private SSH Key' + description: 'Private SSH Key, base64-encoded on a single line (e.g. `base64 -w0 id_ed25519`). A raw PEM key still works but is not masked in the logs.' required: true command: description: 'Shell command or multi-line script to run on the remote server' @@ -36,7 +36,12 @@ runs: # 1. Setup the SSH directory and private key mkdir -p ~/.ssh chmod 700 ~/.ssh - echo "$SSH_KEY" > ~/.ssh/ssh_command_key + # The key is expected base64-encoded so it's a single-line secret the runner can mask; + # raw multi-line PEM keys are still accepted for backwards compatibility. + case "$SSH_KEY" in + *"-----BEGIN"*) echo "$SSH_KEY" > ~/.ssh/ssh_command_key ;; + *) printf '%s' "$SSH_KEY" | tr -d '[:space:]' | base64 -d > ~/.ssh/ssh_command_key ;; + esac chmod 600 ~/.ssh/ssh_command_key # 2. Configure SSH for the custom port/user and bypass host key prompt