Skip to content

fix!: potential secret exposure to templating engine and gitops repo history - #681

Merged
tuunit merged 1 commit into
mainfrom
fix/secret-exposure-to-templating-engine
Oct 9, 2026
Merged

tuunit merged 1 commit into
mainfrom
fix/secret-exposure-to-templating-engine

Conversation

@tuunit

@tuunit tuunit commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

Summary

Breaking change: This PR removes the environment variable map from the template engine scope. As it is a potential security flaw as it can expose secrets to the gitops repository by allowing to template any environment variable contained secret to be templated into arbitrary files.

Change type

  • CLI or Go code
  • Documentation
  • Tests or CI
  • Refactor or cleanup

Breaking change

  • This changes existing behaviour. I explained the migration or impact above.

Catalogs/Services need to migrate away from hardcoded .env references and instead should fully rely on external-secret references.

How I tested it

Notes for reviewers

…history

Signed-off-by: Jan Larwig <jan.larwig@digits.schwarz>
@tuunit
tuunit requested a review from a team October 9, 2026 12:09
@tuunit
tuunit merged commit 40288f0 into main Oct 9, 2026
8 checks passed
@tuunit
tuunit deleted the fix/secret-exposure-to-templating-engine branch October 9, 2026 12:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants