Repository navigation
question: secrets to file system #262
Description
Activity
Which secrets are you referring to? IIRC we might write the node auth token to a file - but that's required by npm. I have no idea how to publish things without relying on
.npmrchttps://docs.github.com/en/actions/publishing-packages/publishing-nodejs-packages
We can use the NODE_AUTH_TOKEN environment variable that the setup node action may give us?
For git instead of netrc, we can perhaps save the credentials temporarily to memory: https://stackoverflow.com/a/36949072
I started this issue because I was looking at the changesets action code and came upon these lines where the environment variable is directly written to the file:
Line 76 in 595655c
`\n//registry.npmjs.org/:_authToken=${process.env.NPM_TOKEN}\n`
Line 83 in 595655c
`//registry.npmjs.org/:_authToken=${process.env.NPM_TOKEN}\n` What you could do instead is just what github says it does and copy the following to the .npmrc file:
//registry.npmjs.org/:_authToken=${NODE_AUTH_TOKEN}I see now in the README that you reference the fact that node sets up an npmrc file with the environment variable => and of course, the code checks for the authToken line, so obviously the code/you/someone is aware of the NPM behavior.
But I also note that the name of the environment variable you suggest using is NPM_TOKEN and not NODE_AUTH_TOKEN. Maybe that reflects an earlier/custom behavior of the setup-node action, although in terms of references, all I could find for auth was this PR), and so node's automatic behavior in theory should not be working.
Presumably, this would actually cause auth errors for anyone using the action, but it seems that
setup-nodeonly writes the npmrc file if aregistry-urlconfig setting is added, and so as long as you don't add that,changesetswould detect that no npmrc file was written, and write its own, with the NPM_TOKEN embedded in cleartext.So I can setup a PR to change the README to suggest using NODE_AUTH_TOKEN like in the github docs, and also change the written npmrc string to use an environment variable instead of actually reading the variable and writing its value.
Let me know what I've misunderstood, I'm sure something!
Any update on this? Why is the Changesets action creating a
.netrcfile with secrets added to the file system?Reacted by Dinko Miletić@bluwy amazing!
This action currently writes secrets to the file system so that they can be useful later by git/npm — would it be preferable/possible to pass the secrets via the environment ?