GHSA-h3q2-8whx-c29h
`goreleaser release --debug` shows secrets
Quick fix
GHSA-h3q2-8whx-c29h — github.com/goreleaser/goreleaser: upgrade to the fixed version with the command below.
go get github.com/goreleaser/goreleaser@v1.24.0Details
### Summary Hello 👋
`goreleaser release --debug` log shows secret values used in the in the custom publisher.
How to reproduce the issue:
- Define a custom publisher as the one below. Make sure to provide a custom script to the `cmd` field and to provide a secret to `env`
``` #.goreleaser.yml publishers: - name: my-publisher # IDs of the artifacts we want to sign ids: - linux_archives - linux_package cmd: "./build/package/linux_notarize.sh" env: - VERSION={{ .Version }} - SECRET_1={{.Env.SECRET_1}} - SECRET_2={{.Env.SECRET_2}} ```
- run `goreleaser release --debug`
You should see your secret value in the gorelease log. The log shows also the `GITHUB_TOKEN`
Example:
``` running cmd= .... SECRET_1=secret_value ```
Are you affected?
Enter the version of the package you're using.
Affected packages
1.23.0Fixed in: 1.24.0go get github.com/goreleaser/goreleaser@v1.24.0