Skip to content

Commit e832aee

Browse files
committedApr 20, 2024
Change the default value of persist-credentials to false
Change the default value of persist-credentials setting from true to false to reduce the risk of unintentionally exposing the GITHUB_TOKEN secret. Fixes: actions#485 Signed-off-by: Michi Mutsuzaki <michi@isovalent.com>
1 parent 1d96c77 commit e832aee

File tree

2 files changed

+3
-3
lines changed

2 files changed

+3
-3
lines changed
 

‎README.md

+2-2
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ This action checks-out your repository under `$GITHUB_WORKSPACE`, so your workfl
66

77
Only a single commit is fetched by default, for the ref/SHA that triggered the workflow. Set `fetch-depth: 0` to fetch all history for all branches and tags. Refer [here](https://docs.github.com/actions/using-workflows/events-that-trigger-workflows) to learn which commit `$GITHUB_SHA` points to for different events.
88

9-
The auth token is persisted in the local git config. This enables your scripts to run authenticated git commands. The token is removed during post-job cleanup. Set `persist-credentials: false` to opt-out.
9+
Set `persist-credentials: true` to opt-in to persist the auth token in the local git config. This enables your scripts to run authenticated git commands. The token is removed during post-job cleanup.
1010

1111
When Git 2.18 or higher is not in your PATH, falls back to the REST API to download the files.
1212

@@ -68,7 +68,7 @@ Please refer to the [release page](https://github.com/actions/checkout/releases/
6868
ssh-user: ''
6969

7070
# Whether to configure the token or SSH key with the local git config
71-
# Default: true
71+
# Default: false
7272
persist-credentials: ''
7373

7474
# Relative path under $GITHUB_WORKSPACE to place the repository

‎action.yml

+1-1
Original file line numberDiff line numberDiff line change
@@ -51,7 +51,7 @@ inputs:
5151
default: git
5252
persist-credentials:
5353
description: 'Whether to configure the token or SSH key with the local git config'
54-
default: true
54+
default: false
5555
path:
5656
description: 'Relative path under $GITHUB_WORKSPACE to place the repository'
5757
clean:

0 commit comments

Comments
 (0)
Failed to load comments.