You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Change the default value of persist-credentials to false
Change the default value of persist-credentials setting from true to
false to reduce the risk of unintentionally exposing the GITHUB_TOKEN
secret.
Fixes: actions#485
Signed-off-by: Michi Mutsuzaki <michi@isovalent.com>
Copy file name to clipboardexpand all lines: README.md
+2-2
Original file line number
Diff line number
Diff line change
@@ -6,7 +6,7 @@ This action checks-out your repository under `$GITHUB_WORKSPACE`, so your workfl
6
6
7
7
Only a single commit is fetched by default, for the ref/SHA that triggered the workflow. Set `fetch-depth: 0` to fetch all history for all branches and tags. Refer [here](https://docs.github.com/actions/using-workflows/events-that-trigger-workflows) to learn which commit `$GITHUB_SHA` points to for different events.
8
8
9
-
The auth token is persisted in the local git config. This enables your scripts to run authenticated git commands. The token is removed during post-job cleanup. Set `persist-credentials: false` to opt-out.
9
+
Set `persist-credentials: true` to opt-in to persist the auth token in the local git config. This enables your scripts to run authenticated git commands. The token is removed during post-job cleanup.
10
10
11
11
When Git 2.18 or higher is not in your PATH, falls back to the REST API to download the files.
12
12
@@ -68,7 +68,7 @@ Please refer to the [release page](https://github.com/actions/checkout/releases/
68
68
ssh-user: ''
69
69
70
70
# Whether to configure the token or SSH key with the local git config
71
-
# Default: true
71
+
# Default: false
72
72
persist-credentials: ''
73
73
74
74
# Relative path under $GITHUB_WORKSPACE to place the repository
0 commit comments