fix(08-fix): WR-05 bind REGISTRY_PAT via env: and pipe with printf for docker login

This commit is contained in:
Lucas Berger
2026-06-11 19:27:03 -04:00
parent 6bcf867e6c
commit 58861d99a8
+8 -1
View File
@@ -59,8 +59,15 @@ jobs:
# Secret is named REGISTRY_PAT (not GITEA_REGISTRY_PAT): Gitea reserves the GITEA_ prefix # Secret is named REGISTRY_PAT (not GITEA_REGISTRY_PAT): Gitea reserves the GITEA_ prefix
# for secret names, so the GITEA_-prefixed name cannot be created. # for secret names, so the GITEA_-prefixed name cannot be created.
- name: Docker login - name: Docker login
# Bind the secret through env: so it is never substituted into the rendered
# script body. Read it as $REGISTRY_PAT and pipe with printf '%s' (echo is not
# safe for arbitrary strings — a trailing newline or shell-significant char
# would mangle the password into a confusing `unauthorized`) (WR-05).
env:
REGISTRY_PAT: ${{ secrets.REGISTRY_PAT }}
run: | run: |
echo "${{ secrets.REGISTRY_PAT }}" | \ set -euo pipefail
printf '%s' "$REGISTRY_PAT" | \
docker login git.bergerhouse.net \ docker login git.bergerhouse.net \
--username luckberg \ --username luckberg \
--password-stdin --password-stdin