`goreleaser release --debug` shows secrets
Moderate severity
GitHub Reviewed
Published
Jan 29, 2024
in
goreleaser/goreleaser
•
Updated Jan 30, 2024
Package
Affected versions
= 1.23.0
Patched versions
1.24.0
Description
Published by the National Vulnerability Database
Jan 30, 2024
Published to the GitHub Advisory Database
Jan 30, 2024
Reviewed
Jan 30, 2024
Last updated
Jan 30, 2024
Summary
Hello 👋
goreleaser release --debug
log shows secret values used in the in the custom publisher.How to reproduce the issue:
cmd
field and to provide a secret toenv
goreleaser release --debug
You should see your secret value in the gorelease log. The log shows also the
GITHUB_TOKEN
Example:
References