Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Explicitly declare the BRUTUS_PAT_TOKEN secret. #90

Merged
merged 1 commit into from
Feb 5, 2024
Merged

Conversation

freakboy3742
Copy link
Member

Explicitly declares the BRUTUS_PAT_TOKEN secret, so that the workflow can be used outside the beeware organization.

Secrets aren't shared with reusable workflows if the workflow is defined in a different organisation. To allow secrets to be used, the secret must be explicitly declared as part of the workflow_call definition.

This was discovered as part of adding pre-commit-update to the dmgbuild repo

From what I can tell, this should have no impact for workflows in the same organization - for those workflows secrets: inherit implicitly passes through all repo, environment and organization secrets.

PR Checklist:

  • All new features have been tested
  • All new features have been documented
  • I have read the CONTRIBUTING.md file
  • I will abide by the code of conduct

@rmartin16
Copy link
Member

From what I can tell, this should have no impact for workflows in the same organization - for those workflows secrets: inherit implicitly passes through all repo, environment and organization secrets.

This makes sense to me...but I can't find anything that confirms secrets: inherit works with explicitly required secrets. I guess I would certainly hope so.

I suppose once this is merged, we can kick off pre-commit-update for a repo and see what it does.

@rmartin16 rmartin16 merged commit c1afc89 into main Feb 5, 2024
69 checks passed
@rmartin16 rmartin16 deleted the org-secrets branch February 5, 2024 02:30
@rmartin16
Copy link
Member

Runs well enough for Briefcase 👍🏼

https://github.com/beeware/briefcase/actions/runs/7778799680

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants