-
-
Notifications
You must be signed in to change notification settings - Fork 306
Closed as not planned
Description
I propose this suggestion while acknowledging that it may be considered a non-recommended flow.
I understand that rejection of this proposal is a natural possibility.
Necessity for Aftercare
- There's a possibility that users might unknowingly continue using the latest version without realizing that Secrets have been exposed.
Here's the detailed proposal
- Append the build metadata "+org" to all existing tags.
- Update all existing tags to a commit that outputs the following error message
Please take the following actions:
1. Rotate your Secrets as they may have been compromised.
2. Either update to version v46.0.0 or later, or if you need to use the current version, specify vX.Y.Z+org.
This will at least let you know that secrets need to be rotated if the user is using a problematic version at the time of the action.
menzenski, houserx-jmcc, knedl1k, linchun3, hammzj and 7 more
Metadata
Metadata
Assignees
Labels
No labels