From 001cba3953812df1d8df690f43c8124da9f7ac17 Mon Sep 17 00:00:00 2001 From: Miley Hollenberg Date: Mon, 28 Sep 2026 13:48:58 +0200 Subject: [PATCH] Accept the SSH private key base64-encoded Multi-line secrets aren't masked by the runner, so a raw PEM key passed as private_key ends up in plain text in the step's env block in the log. Accept a single-line base64-encoded key instead, which is masked like any other secret. Raw PEM keys still work for backwards compatibility. Co-Authored-By: Claude Opus 5.5 --- action.yml | 9 +++++++-- 1 file changed, 7 insertions(+), 2 deletions(-) diff --git a/action.yml b/action.yml index d578944..bb6701a 100644 --- a/action.yml +++ b/action.yml @@ -14,7 +14,7 @@ inputs: description: 'SSH Username' required: true private_key: - description: 'SSH Private Key' + description: 'SSH Private Key, base64-encoded on a single line (e.g. `base64 -w0 id_ed25519`). A raw PEM key still works but is not masked in the logs.' required: true transfers: description: 'List of transfers formatted as "source_file(s) | remote_destination". One per line.' @@ -34,7 +34,12 @@ runs: run: | # 1. Create a secure temporary file for the SSH key SSH_KEY_PATH=$(mktemp) - printf '%s\n' "$PRIVATE_KEY" > "$SSH_KEY_PATH" + # The key is expected base64-encoded so it's a single-line secret the runner can mask; + # raw multi-line PEM keys are still accepted for backwards compatibility. + case "$PRIVATE_KEY" in + *"-----BEGIN"*) printf '%s\n' "$PRIVATE_KEY" > "$SSH_KEY_PATH" ;; + *) printf '%s' "$PRIVATE_KEY" | tr -d '[:space:]' | base64 -d > "$SSH_KEY_PATH" ;; + esac chmod 600 "$SSH_KEY_PATH" # 2. Add Host to known_hosts to prevent verification prompts