GitHub Actions: Organization secrets
github.blog
github.blog
btw, if you're looking for an intro to github actions, i put out a video last december covering publishing your first github action workflow: https://youtu.be/J4EhgEskSZA
Assuming some of those are open source, would you please link to them?
Nothing to be done about internal parties except policies.
[1] https://help.github.com/en/actions/hosting-your-own-runners/...
It could be as simple as calling a metadata API only available from inside a GitHub Actions container and obtain a oauth2 token/JWT for an external audience.
Why not give us some signed JWTs for external authentication.
Secrets is only good for legacy systems.
This is very welcome, now how about organization-level branch protections please!
https://developer.github.com/v3/actions/secrets/#get-a-repos...
and the blog states the same behavior I'm seeing in the docs:
First, the API doesn’t return any values, only names.
https://github.blog/2020-02-06-manage-secrets-and-more-with-...