From c063688b75dad2e9c56625f2a60205ed49cd53c7 Mon Sep 17 00:00:00 2001 From: bitdeals Date: Fri, 7 Aug 2026 13:38:54 +0000 Subject: [PATCH] ci: pass the registry password on stdin, fail on a failed push A password in argv is world-readable through /proc/PID/cmdline while the command runs; docker warns about it for that reason. The environment of a process is readable by its owner alone, so $PASS itself was never the problem. The two pushes are joined with && rather than left as separate statements: the step's exit code is the last command's, so the intent is now explicit instead of resting on whatever -e flag the runner's shell happens to carry. --- .gitea/workflows/build.yaml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.gitea/workflows/build.yaml b/.gitea/workflows/build.yaml index 05f8be0..0dc1fc5 100644 --- a/.gitea/workflows/build.yaml +++ b/.gitea/workflows/build.yaml @@ -31,9 +31,9 @@ jobs: --tag "${REGISTRY}/${REPOSITORY##*/}:latest" - name: Docker login run: | - docker login --username "$USER" --password "$PASS" "$REGISTRY" + echo "$PASS" | docker login --username "$USER" --password-stdin "$REGISTRY" - name: Push images to registry run: | - docker push "${REGISTRY}/${REPOSITORY##*/}:${VERSION}.${COMMIT::7}" ; \ + docker push "${REGISTRY}/${REPOSITORY##*/}:${VERSION}.${COMMIT::7}" && \ docker push "${REGISTRY}/${REPOSITORY##*/}:latest"