Commit Graph
5 Commits
Author SHA1 Message Date
megamileyandClaude Opus 5.5 001cba3953 Accept the SSH private key base64-encoded
Multi-line secrets aren't masked by the runner, so a raw PEM key passed
as private_key ends up in plain text in the step's env block in the log.
Accept a single-line base64-encoded key instead, which is masked like
any other secret. Raw PEM keys still work for backwards compatibility.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-28 13:48:58 +02:00
Claude 89086c4163 Fix private key leaking into step logs
Composite actions substitute ${{ inputs.* }} directly into the run:
script source before execution, and the runner echoes that resolved
script at the top of the step log. Interpolating private_key and
transfers straight into the heredocs meant the raw SSH private key
was printed in plaintext on every run. Move both through env: and
reference them as shell variables instead, matching ssh-checkout and
ssh-command.
2026-08-06 08:47:21 +00:00
megamiley f6a66c462d Update action.yml 2026-08-05 13:38:02 +00:00
megamiley 69592ce311 Update action.yml 2026-08-04 19:04:57 +00:00
megamiley 09f3c00aac Add action.yml 2026-06-16 07:00:30 +00:00