fix(cli): update infisical installation script and mask secrets line-by-line in logs

This commit is contained in:
2026-08-05 22:33:34 +02:00
parent 4462f57066
commit 839a452087
2 changed files with 8 additions and 3 deletions
+7 -2
View File
@@ -43,7 +43,7 @@ jobs:
- name: Install Infisical CLI
run: |
curl -1sLf 'https://dl.cloudsmith.io/public/infisical/infisical-cli/setup.deb.sh' | sudo -E bash
curl -1sLf 'https://artifacts-cli.infisical.com/setup.deb.sh' | sudo -E bash
sudo apt-get update && sudo apt-get install -y infisical
- name: Fetch secrets from Infisical
@@ -68,7 +68,12 @@ jobs:
# Mask and write all secrets to GITHUB_ENV
while IFS= read -r -d '' key && IFS= read -r -d '' value; do
echo "::add-mask::$value"
# Mask each line of the value individually to ensure multiline values are fully masked in the logs
while IFS= read -r line; do
if [ -n "$line" ]; then
echo "::add-mask::$line"
fi
done <<< "$value"
# Use multi-line syntax to support keys like SSH keys which have newlines
EOF_DELIMITER="EOF_${key}_${RANDOM}"