fix: sync-secrets wrote "-" as the value of every secret it synced

`gh secret set` reads the value from stdin only when --body is NOT passed.
`--body -` does not mean "read stdin" - gh takes it literally - so

    echo "$value" | gh secret set "$name" -R "$TARGET_REPO" --body -

piped the real value into a process that ignored stdin, and stored the
single character "-" instead. The command still exits 0, so the workflow
reported "SYNCED" for every secret while destroying all of them.

Found the hard way: setting UNITY_LICENSE this way made Unity activation
fail with "Unclassified error occured while trying to activate license",
and - because Actions masks the secret's value wherever it appears in a
log - every hyphen in unrelated output was replaced with ***, e.g.

    Unable to find image 'unityci/editor:ubuntu***2022.3.7f1***linux***il2cpp***3'

which is what made the real cause obvious.

Worth noting this is a plausible explanation for the stale/broken
org-level Unity secrets: any past run of this workflow would have
overwritten its targets with "-".

Passes the value via --body directly. Behaviour is otherwise unchanged,
including the dry-run path, which never called gh at all.
This commit is contained in:
frostebite
2026-08-24 22:58:05 +01:00
parent c8afce7158
commit fc8c870695
+8 -1
View File
@@ -70,7 +70,14 @@ jobs:
if [ "$DRY_RUN" = "true" ]; then
echo "🔍 DRY RUN: would sync $name → $TARGET_REPO"
else
if echo "$value" | gh secret set "$name" -R "$TARGET_REPO" --body - 2>/dev/null; then
# `gh secret set` reads the value from stdin only when --body is
# NOT passed. `--body -` does not mean "read stdin" - gh takes it
# literally, so this wrote the single character "-" as the value
# of every secret it synced, silently destroying them. (A secret
# whose value is "-" also makes Actions mask every hyphen in the
# logs, which mangles unrelated output like image tags:
# "unityci/editor:ubuntu***2022.3.7f1***linux***il2cpp***3".)
if gh secret set "$name" -R "$TARGET_REPO" --body "$value" 2>/dev/null; then
echo "✅ SYNCED: $name → $TARGET_REPO"
else
echo "⚠️ FAILED: $name → $TARGET_REPO (continuing)"