diff --git a/.github/workflows/sync-secrets.yml b/.github/workflows/sync-secrets.yml index b2af4e83..cae90612 100644 --- a/.github/workflows/sync-secrets.yml +++ b/.github/workflows/sync-secrets.yml @@ -70,7 +70,14 @@ jobs: if [ "$DRY_RUN" = "true" ]; then echo "🔍 DRY RUN: would sync $name → $TARGET_REPO" else - if echo "$value" | gh secret set "$name" -R "$TARGET_REPO" --body - 2>/dev/null; then + # `gh secret set` reads the value from stdin only when --body is + # NOT passed. `--body -` does not mean "read stdin" - gh takes it + # literally, so this wrote the single character "-" as the value + # of every secret it synced, silently destroying them. (A secret + # whose value is "-" also makes Actions mask every hyphen in the + # logs, which mangles unrelated output like image tags: + # "unityci/editor:ubuntu***2022.3.7f1***linux***il2cpp***3".) + if gh secret set "$name" -R "$TARGET_REPO" --body "$value" 2>/dev/null; then echo "✅ SYNCED: $name → $TARGET_REPO" else echo "⚠️ FAILED: $name → $TARGET_REPO (continuing)"