Skip to content

question: secrets to file system #262

Description

@yaacovCR

This action currently writes secrets to the file system so that they can be useful later by git/npm — would it be preferable/possible to pass the secrets via the environment ?

Activity

  1. Andarist commented on Feb 21, 2023

    @Andarist
    Member

    Which secrets are you referring to? IIRC we might write the node auth token to a file - but that's required by npm. I have no idea how to publish things without relying on .npmrc

  2. yaacovCR commented on Feb 21, 2023

    @yaacovCR
    Author

    https://docs.github.com/en/actions/publishing-packages/publishing-nodejs-packages

    We can use the NODE_AUTH_TOKEN environment variable that the setup node action may give us?

    For git instead of netrc, we can perhaps save the credentials temporarily to memory: https://stackoverflow.com/a/36949072

  3. yaacovCR commented on Feb 24, 2023

    @yaacovCR
    Author

    I started this issue because I was looking at the changesets action code and came upon these lines where the environment variable is directly written to the file:

    `\n//registry.npmjs.org/:_authToken=${process.env.NPM_TOKEN}\n`

    `//registry.npmjs.org/:_authToken=${process.env.NPM_TOKEN}\n`

    What you could do instead is just what github says it does and copy the following to the .npmrc file:
    //registry.npmjs.org/:_authToken=${NODE_AUTH_TOKEN}

    I see now in the README that you reference the fact that node sets up an npmrc file with the environment variable => and of course, the code checks for the authToken line, so obviously the code/you/someone is aware of the NPM behavior.

    But I also note that the name of the environment variable you suggest using is NPM_TOKEN and not NODE_AUTH_TOKEN. Maybe that reflects an earlier/custom behavior of the setup-node action, although in terms of references, all I could find for auth was this PR), and so node's automatic behavior in theory should not be working.

    Presumably, this would actually cause auth errors for anyone using the action, but it seems that setup-node only writes the npmrc file if a registry-url config setting is added, and so as long as you don't add that, changesets would detect that no npmrc file was written, and write its own, with the NPM_TOKEN embedded in cleartext.

    So I can setup a PR to change the README to suggest using NODE_AUTH_TOKEN like in the github docs, and also change the written npmrc string to use an environment variable instead of actually reading the variable and writing its value.

    Let me know what I've misunderstood, I'm sure something!

  4. cseas commented on Dec 24, 2024

    @cseas

    Any update on this? Why is the Changesets action creating a .netrc file with secrets added to the file system?

  5. yaacovCR commented on Jul 28, 2026

    @yaacovCR
    Author

    @bluwy amazing!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions