Urgent.News

What's breaking now, across thousands of outlets.

Tech

GitHub Actions Secrets: 8 Common Mistakes and Fixes

You build a small automation that posts to Discord when your website goes down. To make it work, you paste the webhook URL into your script. It works on the first try, so you commit it and move on. Months later, you make the repo public to share it. Now anyone can read that URL, and anyone can post to your Discord channel. Secrets are one of those things that feel like a small detail until they…

GitHub Actions Secrets: 8 Common Mistakes and Fixes

GitHub Actions provide a powerful way to automate tasks, but they also introduce the risk of secrets leakage if not managed properly. This article outlines eight common mistakes developers make when handling secrets in GitHub Actions and provides solutions to avoid these issues. Secrets in GitHub Actions include API keys, passwords, tokens, and webhook URLs.

The first mistake is hardcoding secrets directly in files, which can be avoided by storing them as repository secrets in the GitHub settings. Another common mistake is printing secrets in logs, which can be prevented by removing debug commands or printing whether a secret is empty. Trusting GitHub's log masking is also unreliable, so it's better to store each secret as a single value and use the `::add-mask` command to hide sensitive values.

Using overly powerful keys can lead to significant damage if leaked, so it's essential to grant the smallest permission required and use separate keys for each project. Using restricted keys for services like Bluesky bots can further enhance security.

Brief written by urgent.news from Dev.to's own syndicated text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Hacktoberfest Weekend Challenge

This is a submission for the Hacktoberfest Weekend Challenge: Build for a Friend What I Built One Liner is a one-page web app that turns long, over-the-top posts into a single line saying what they…

  • One Liner app condenses long posts into single lines
  • App runs entirely on user's device, no data shared
  • Open-weight models used locally via WebLLM and WebGPU

Sanity vs Payload CMS vs Contentful: Pricing Comparison 2026

Sanity, Payload CMS, and Contentful pricing in 2026 looks radically different depending on how you count. Sanity charges per project and API usage, Payload is open-source but carries real…

  • Sanity charges per project and API usage, with a free tier for small sites.
  • Payload CMS is open-source with infrastructure costs, offering self-hosting options.
  • Contentful bills per seat with steep price increases at scale, suitable for larger teams.

Zinc Whiskers: The Silent Contamination Threat Under AI Data Center Floors

A Routine Maintenance Check Turns Into Sudden AI Cluster Failure In the controlled environment of a large-scale data center supporting continuous AI model training, technicians initiated a scheduled…

  • Technicians discovered zinc whiskers on underfloor system during routine inspection.
  • Whiskers originated from electroplated hardware and traveled via high-velocity airflow.
  • Recovery involved replacing components, installing filters, and switching materials.

More from Saturday 3 October →