Travis CI fork pull request builds cannot access encrypted environment variables
0 reputation · 04 Jun 2026, 02:39 UTC
On the current travis-ci.com platform, builds for pull requests opened from forks of a public repository do not receive the encrypted environment variables defined in .travis.yml (secure: entries) or in repository settings. The isolation is deliberate: build logs for public repositories are public, and Travis CI withholds secrets from builds whose scripts an outside contributor can modify.
The difficulty is the all-or-nothing model. Fork PR builds may legitimately need credentials for integration tests, yet there appears to be no per-contributor, per-variable, or per-PR mechanism to expose specific secrets to a trusted fork build. The “Build fork pull requests” setting only controls whether such builds trigger, and variables created with travis encrypt appear to follow the same restriction as those added through the settings UI.
- Does travis-ci.com offer any supported way to grant encrypted environment variables to a selected fork pull request or trusted external contributor without exposing them to every fork build?
- If not, which documented configuration keeps fork PR builds useful while preserving secret isolation?
- Is the restriction identical for
secure:variables and settings-defined variables on the current platform?