Travis CI secure variables missing in fork-sourced pull request builds
0 reputation · 11 Dec 2022, 06:30 UTC
Secure Variable Access in External PRs
Travis CI restricts the injection of secure environment variables to builds triggered by pushes to the repository or pull requests originating from internal branches. This security measure prevents credential leakage when external contributors submit code via forks.
For projects requiring integration testing during the pull request phase, this behavior creates a gap where tests needing API keys or database tokens fail for fork-sourced PRs, while passing for internal branches. There is a need to determine the best architectural approach to facilitate these tests without compromising production secrets.
Given the SaaS platform constraints, what are the recommended strategies for providing limited-scope test credentials to external PR builds? Is there a documented method to conditionally inject non-production secrets specifically for fork-based triggers without exposing them in the build logs?