4 ms·
That wouldn't be possible, and that's independent of the security issue we've disclosed in the post. For pull requests Travis CI has long had security measures
by roidrage 9y ago
That wouldn't be possible, and that's independent of the security issue we've disclosed in the post.
For pull requests Travis CI has long had security measures in place to prevent this scenario from happening: https://docs.travis-ci.com/user/pull-requests#Pull-Requests-and-Security-Restrictions https://docs.travis-ci.com/user/pull-requests#Pull-Requests-...
- tehlike 9y agoDoesnt this still make it potentially available in case some malicious/unmalicious coder leaves some console debugging out?
- nothrabannosir 9y agoOnly if you merge it in. The point is the secure environment variables are not available at all in the fork build. The bash oneliner they show is to help you run scripts which won't crash if they don't have those env vars available, not to "hide them" by running a test script which doesn't use them.
- tehlike 9y agoI know many instances where code reviews didnt catch log statement in huge binaries.
- nothrabannosir 9y agoRight, but now you're in the "review of a PR didn't catch malicious code" boat. At which point, you've got bigger problems than leaking env vars in your CI. Not to dismiss it---it's just a different point.