Skip to content

Aftercare for Users of Versions with Potentially Exposed Secrets #2477

@ryo-kagawa

Description

@ryo-kagawa

I propose this suggestion while acknowledging that it may be considered a non-recommended flow.
I understand that rejection of this proposal is a natural possibility.

Necessity for Aftercare

  • There's a possibility that users might unknowingly continue using the latest version without realizing that Secrets have been exposed.

Here's the detailed proposal

  1. Append the build metadata "+org" to all existing tags.
  2. Update all existing tags to a commit that outputs the following error message
Please take the following actions:
1. Rotate your Secrets as they may have been compromised.
2. Either update to version v46.0.0 or later, or if you need to use the current version, specify vX.Y.Z+org.

This will at least let you know that secrets need to be rotated if the user is using a problematic version at the time of the action.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions