Give Bitrise one secret and split the docs by audience - #582
Draft
kieran-osgood-shopify wants to merge 1 commit into
Draft
Give Bitrise one secret and split the docs by audience#582kieran-osgood-shopify wants to merge 1 commit into
kieran-osgood-shopify wants to merge 1 commit into
Conversation
This was referenced Aug 5, 2026
Contributor
Author
This was referenced Aug 5, 2026
kieran-osgood-shopify
force-pushed
the
kieran-osgood/ejson-ci-and-docs
branch
from
August 5, 2026 11:06
76f072a to
ce17650
Compare
kieran-osgood-shopify
force-pushed
the
kieran-osgood/ejson-run-maestro-e2e-env
branch
from
August 5, 2026 11:06
bebc4d0 to
1dc2560
Compare
kieran-osgood-shopify
force-pushed
the
kieran-osgood/ejson-ci-and-docs
branch
from
August 5, 2026 11:35
ce17650 to
88b6724
Compare
kieran-osgood-shopify
force-pushed
the
kieran-osgood/ejson-run-maestro-e2e-env
branch
2 times, most recently
from
August 5, 2026 11:45
39b95df to
a8cf7ad
Compare
kieran-osgood-shopify
force-pushed
the
kieran-osgood/ejson-ci-and-docs
branch
from
August 5, 2026 11:45
88b6724 to
a2af77b
Compare
Bitrise held nine project secrets that had to stay aligned with what the suite reads. It now holds EJSON_PRIVATE_KEY only. bitrise_ci_helpers installs a pinned ejson2env, verifies its checksum, writes the key into a keydir, and runs generate_env_files, so CI decrypts the same committed files a developer does. The key reaches the keydir through a redirect and the credentials reach envman through a file, so neither enters an argument list or the build log. Installing the key is idempotent, because the mode it sets makes the file unwritable. e2e-execute-browserstack-run builds no app, so it exports the account credentials itself; every other workflow gets them through a sample app build. The docs stop describing prompts that no longer exist and say plainly which audience does what: employees run `dev secrets edit`, external contributors copy .env.example and keep their file. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Assisted-By: devx/252dfd24-6c25-4bb4-8463-27702ec564eb
kieran-osgood-shopify
force-pushed
the
kieran-osgood/ejson-run-maestro-e2e-env
branch
from
August 5, 2026 12:33
a8cf7ad to
b2235cf
Compare
kieran-osgood-shopify
force-pushed
the
kieran-osgood/ejson-ci-and-docs
branch
from
August 5, 2026 12:33
a2af77b to
22eb2d4
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

What changes are you making?
How to test
Before you merge
Important
platforms/swift/README.mdand/orplatforms/android/README.md)Releasing a new Swift version?
ShopifyCheckoutKit.podspecplatforms/swift/Sources/ShopifyCheckoutKit/ShopifyCheckoutKit.swiftplatforms/swift/README.md(major version only)Releasing a new Embedded Checkout Protocol version?
embeddedCheckoutProtocolAndroidinplatforms/android/gradle/libs.versions.tomlprotocol/languages/kotlin/embedded-checkout-protocol/api/embedded-checkout-protocol.apiif the public API changedReleasing a new Android version?
checkoutKitAndroidinplatforms/android/gradle/libs.versions.tomlplatforms/android/README.mdTip
See the Contributing documentation for the full release process per platform.