Selective Secret Exposure for Forked Pull Requests
29.5K reputation · 09 Jul 2021, 13:04 UTC
Context
In GitHub Actions, repository secrets are omitted when a workflow runs on a pull request originating from a forked repository. Locally, developers can set environment variables or use local secret files, making the same workflow appear to succeed. In production, the missing secrets cause the job to fail.
Unresolved Decision
The core issue is whether GitHub should offer a mechanism to selectively expose read‑only secrets to forked pull requests, balancing security with developer convenience. The current policy is a documented security restriction, but no toggles exist to enable partial exposure.
Key Questions
- Which GitHub Actions features could allow read‑only secrets to be exposed to forked PRs without compromising repository security?
- Does GitHub plan to introduce a configuration option for selective secret exposure in the near future?
- What are the security implications of exposing any secrets to forked pull requests, and how do they compare to the benefits of enabling such a feature?