Skip to content

[POC][DO NOT MERGE] CI secret-exposure audit (names only) - #265

Open
alikabeel-spooner wants to merge 1 commit into
WeTransfer:masterfrom
alikabeel-spooner:poc/ci-secret-exposure-audit
Open

alikabeel-spooner wants to merge 1 commit into
WeTransfer:masterfrom
alikabeel-spooner:poc/ci-secret-exposure-audit

Conversation

@alikabeel-spooner

Copy link
Copy Markdown
Contributor

⚠️ POC / DO NOT MERGE. This PR intentionally executes a benign, audit-only change from a fork to test whether the Bitrise PR workflow exposes secrets to PR builds. It prints variable names only — never values — and makes no external calls. Close without merging.

What this validates

The PR pipeline triggers on pull_request_source_branch: "*" and runs Bitrise/Scripts/pr_assignments.sh from the checked-out PR tree before any gate (Bitrise/testing_bitrise.yml:21). This PR prepends a presence check that reports which of the CI secret env vars are defined in the PR build environment.

The change

A single block prepended to Bitrise/Scripts/pr_assignments.sh:

  • iterates a fixed list of known secret var names
  • echoes EXPOSED: <NAME> if set, absent : <NAME> if not
  • tests only ${!v:-} — no values, no curl, no external endpoint

Expected result

In the Bitrise log for the Assign PR author and configure CI Testing mode step, read the EXPOSED: / absent : lines. EXPOSED: = defined and exposed to this PR build. Values are masked by Bitrise, so only names are visible.

Scope

POC only. No secrets printed. No external transmission. To be closed immediately after the CI log is read.

POC only - prints which secret env var names are present in the PR build
environment (names only, never values). DO NOT MERGE.

🤖 Generated with [OpenCode](https://opencode.ai)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant