On this page
Does the repository carry the CI secrets its publish pipelines declare? Presence only, never a value, and fail-closed: an unanswerable probe is unknown.
#rlsbl.ci_secrets
#rlsbl.ci_secrets
Does the repository carry the CI secrets its publish pipelines need?
Which secrets those are is each PIPELINE's own answer -- ci_secret_names(), declared on the pipeline class beside the workflow templates that read the secret -- so this module never tests a pipeline type by name. npm declares NPM_TOKEN, maven-central declares its Central Portal credentials and GPG signing key, hex declares HEX_API_KEY; a pypi pipeline declares none, because its workflow authenticates through OIDC trusted publishing and demanding a token there would be wrong, and neither does the GitHub Packages maven pipeline, whose workflow uses the automatic secrets.GITHUB_TOKEN.
A publish pipeline that authenticates with a repository secret fails at the last possible moment when the secret is absent: the release has already tagged, pushed and created the GitHub Release, and the publish job dies with ENEEDAUTH against the registry. The secret's presence is knowable long before that, from the repository itself.
Only PRESENCE is read, never a value. gh answers whether a secret exists; its value is not retrievable through the API at all, and rlsbl never puts a credential on a pipe (see :mod:rlsbl.observe_allowlist).
Fail-closed: a probe that cannot answer -- no credential, no network, an API error, a preview that recorded the call -- is "unknown", and the caller treats unknown as an error. "We could not ask" is not evidence that the secret is there, and a release that trusted it would discover otherwise after tagging.
#probe_repo_secret
def probe_repo_secret(slug, name, *, timeout=15)Does the GitHub repository slug have an Actions secret called name?
Returns {"status": "present"}, {"status": "absent"}, or {"status": "unknown", "message": ...}. A 404 from this endpoint is the API's way of saying the secret does not exist; every other non-zero exit is unknown, because a permission or network failure must never read as absence (or as presence).
#required_ci_secrets
def required_ci_secrets(config){secret_name: [pipeline names]} for the configured CI pipelines.
Which secret a pipeline's CI job authenticates with is the PIPELINE's own answer (ci_secret_names, declared beside the workflow templates that read it), never a type name tested here: a pipeline publishing through OIDC trusted publishing needs no secret at all, and a local: true pipeline authenticates from the developer's own environment.
#secret_remedy
def secret_remedy(slug, secret)The command that sets secret on slug from the local credential.
NPM_TOKEN has a documented one-liner that reads the token out of the developer's own ~/.npmrc; any other secret -- the Maven Central credentials, a GPG signing key, a hex.pm API key -- gets the same command with the value left for the operator to supply, since rlsbl knows no source for it and must not invent one.
#SecretVerdict
Result of probing one repository for the secrets its pipelines need.
#ok
def ok(self)#evaluate_ci_secret_presence
def evaluate_ci_secret_presence(config, slug, *, probe=probe_repo_secret)Every secret the configured CI publish pipelines need must exist.