VDB
Sign up
MEDIUM5.5

GHSA-h3q2-8whx-c29h

`goreleaser release --debug` shows secrets

Quick fix

GHSA-h3q2-8whx-c29h — github.com/goreleaser/goreleaser: upgrade to the fixed version with the command below.

go get github.com/goreleaser/goreleaser@v1.24.0

Details

### Summary Hello 👋

`goreleaser release --debug` log shows secret values used in the in the custom publisher.

How to reproduce the issue:

- Define a custom publisher as the one below. Make sure to provide a custom script to the `cmd` field and to provide a secret to `env`

``` #.goreleaser.yml publishers: - name: my-publisher # IDs of the artifacts we want to sign ids: - linux_archives - linux_package cmd: "./build/package/linux_notarize.sh" env: - VERSION={{ .Version }} - SECRET_1={{.Env.SECRET_1}} - SECRET_2={{.Env.SECRET_2}} ```

- run `goreleaser release --debug`

You should see your secret value in the gorelease log. The log shows also the `GITHUB_TOKEN`

Example:

``` running cmd= .... SECRET_1=secret_value ```

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/goreleaser/goreleaser
Introduced in: 1.23.0Fixed in: 1.24.0
Fixgo get github.com/goreleaser/goreleaser@v1.24.0

References