Skip to content
rlsbl.ci_secrets
On this page

Does the repository carry the CI secrets its publish pipelines declare? Presence only, never a value, and fail-closed: an unanswerable probe is unknown.

#rlsbl.ci_secrets

#rlsbl.ci_secrets

Does the repository carry the CI secrets its publish pipelines need?

Which secrets those are is each PIPELINE's own answer -- ci_secret_names(), declared on the pipeline class beside the workflow templates that read the secret -- so this module never tests a pipeline type by name. npm declares NPM_TOKEN, maven-central declares its Central Portal credentials and GPG signing key, hex declares HEX_API_KEY; a pypi pipeline declares none, because its workflow authenticates through OIDC trusted publishing and demanding a token there would be wrong, and neither does the GitHub Packages maven pipeline, whose workflow uses the automatic secrets.GITHUB_TOKEN.

A publish pipeline that authenticates with a repository secret fails at the last possible moment when the secret is absent: the release has already tagged, pushed and created the GitHub Release, and the publish job dies with ENEEDAUTH against the registry. The secret's presence is knowable long before that, from the repository itself.

Only PRESENCE is read, never a value. gh answers whether a secret exists; its value is not retrievable through the API at all, and rlsbl never puts a credential on a pipe (see :mod:rlsbl.observe_allowlist).

Fail-closed: a probe that cannot answer -- no credential, no network, an API error, a preview that recorded the call -- is "unknown", and the caller treats unknown as an error. "We could not ask" is not evidence that the secret is there, and a release that trusted it would discover otherwise after tagging.

#probe_repo_secret

python
def probe_repo_secret(slug, name, *, timeout=15)

Does the GitHub repository slug have an Actions secret called name?

Returns {"status": "present"}, {"status": "absent"}, or {"status": "unknown", "message": ...}. A 404 from this endpoint is the API's way of saying the secret does not exist; every other non-zero exit is unknown, because a permission or network failure must never read as absence (or as presence).

#required_ci_secrets

python
def required_ci_secrets(config)

{secret_name: [pipeline names]} for the configured CI pipelines.

Which secret a pipeline's CI job authenticates with is the PIPELINE's own answer (ci_secret_names, declared beside the workflow templates that read it), never a type name tested here: a pipeline publishing through OIDC trusted publishing needs no secret at all, and a local: true pipeline authenticates from the developer's own environment.

#secret_remedy

python
def secret_remedy(slug, secret)

The command that sets secret on slug from the local credential.

NPM_TOKEN has a documented one-liner that reads the token out of the developer's own ~/.npmrc; any other secret -- the Maven Central credentials, a GPG signing key, a hex.pm API key -- gets the same command with the value left for the operator to supply, since rlsbl knows no source for it and must not invent one.

#SecretVerdict

Result of probing one repository for the secrets its pipelines need.

#ok

python
def ok(self)

#evaluate_ci_secret_presence

python
def evaluate_ci_secret_presence(config, slug, *, probe=probe_repo_secret)

Every secret the configured CI publish pipelines need must exist.

Search