docs icon indicating copy to clipboard operation
docs copied to clipboard

Add clarity to the use of `::add-mask::` and best practices

Open nbobo-godaddy opened this issue 3 years ago • 3 comments

Code of Conduct

What article on docs.github.com is affected?

What part(s) of the article would you like to see updated?

In the following linked comments @ericsampson mentions best practice use of the ::add-mask:: command. This is important because improper use (as noted in the issue) could result in exfiltration of plaintext secret values in workflow logs before being masked. The documentation at its current state doesn't make this clear enough and an explicit callout could save implementation time and ensure proper use.

Additional information

  • https://github.com/actions/runner/issues/475#issuecomment-635639896
  • https://github.com/actions/runner/issues/475#issuecomment-635750237
  • https://github.com/actions/runner/issues/475#issuecomment-636238383
  • https://github.com/actions/runner/issues/475#issuecomment-742271143

nbobo-godaddy avatar Feb 01 '22 21:02 nbobo-godaddy

Thanks for opening this issue. A GitHub docs team member should be by to give feedback soon. In the meantime, please check out the contributing guidelines.

welcome[bot] avatar Feb 01 '22 21:02 welcome[bot]

@nbobo-godaddy Thanks so much for opening an issue! I'll triage this for the team to take a look :eyes:

ramyaparimi avatar Feb 02 '22 13:02 ramyaparimi

Thank you for opening this issue! This sounds like a great addition to the docs. You or anyone else is welcome to open a PR.

skedwards88 avatar Feb 07 '22 20:02 skedwards88