Forked code should not automatically receive secrets
If somebody can open a pull request that runs your pipeline with your secrets, they can take your secrets.
It is a well-known pattern and still a common misconfiguration, because the convenient default is for everything to run the same way. Builds from untrusted sources need to run without credentials, or not automatically at all.
More on CI/CD security
- A deployment pipeline is a privileged production pathIt goes straight over the gate
- Code review does not protect a compromised runnerNobody looked inside the machine
- Branch protection does not protect every release pathThe gate only guards its own road
- Deployment credentials should match deployment scopeOne bolt across all three
- Build logs can become secret leaksThe log is a page, and people read pages
- Self-hosted runners inherit local trustYou gave the job a desk indoors
