Skip to content

Conversation

@BYK
Copy link
Member

@BYK BYK commented Nov 27, 2025

This patch removes all environment variables except for version-related craft env vars and GITHUB_TOKEN when running the post-releas script to prevent sensitive token data leakage. Note that the script still has file-system access so anything sensitive stored there can be exfiltrated.

This patch removes all environment variables except for version-related craft env vars and GITHUB_TOKEN when running the `post-releas` script to prevent sensitive token data leakage. Note that the script still has file-system access so anything sensitive stored there can be exfiltrated.
@BYK BYK enabled auto-merge (squash) November 27, 2025 21:24
@BYK BYK requested review from Jeffreyhung and oioki November 27, 2025 23:58
@BYK BYK merged commit 55d994b into master Nov 28, 2025
14 checks passed
@BYK BYK deleted the byk/fix/tighten-post-release branch November 28, 2025 15:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants