Skip to content
rlsbl.ci_secrets
On this page

Does the repository carry the CI secrets its publish pipelines declare? Presence only, never a value, and fail-closed: an unanswerable probe is unknown.

#rlsbl.ci_secrets

#rlsbl.ci_secrets

Does the repository carry the CI secrets its publish pipelines need?

Which secrets those are is each PIPELINE's own answer -- ci_secret_names(), declared on the pipeline class beside the workflow templates that read the secret -- so this module never tests a pipeline type by name. npm declares NPM_TOKEN, maven-central declares its Central Portal credentials and GPG signing key, hex declares HEX_API_KEY; a pypi pipeline declares none, because its workflow authenticates through OIDC trusted publishing and demanding a token there would be wrong, and neither does the GitHub Packages maven pipeline, whose workflow uses the automatic secrets.GITHUB_TOKEN.

A publish pipeline that authenticates with a repository secret fails at the last possible moment when the secret is absent: the release has already tagged, pushed and created the GitHub Release, and the publish job dies with ENEEDAUTH against the registry. The secret's presence is knowable long before that, from the repository itself.

Only PRESENCE is read, never a value. gh answers whether a secret exists; its value is not retrievable through the API at all, and rlsbl never puts a credential on a pipe (see :mod:rlsbl.observe_allowlist).

Fail-closed: a probe that cannot answer -- no credential, no network, an API error, a preview that recorded the call -- is "unknown", and the caller treats unknown as an error. "We could not ask" is not evidence that the secret is there, and a release that trusted it would discover otherwise after tagging.

#probe_repo_secret

python
def probe_repo_secret(slug, name, *, timeout=15)

Does the GitHub repository slug have an Actions secret called name?

Returns {"status": "present"}, {"status": "absent"}, or {"status": "unknown", "message": ...}. A 404 from this endpoint is the API's way of saying the secret does not exist; every other non-zero exit is unknown, because a permission or network failure must never read as absence (or as presence).

#required_ci_secrets

python
def required_ci_secrets(config)

{secret_name: [pipeline names]} for the configured CI pipelines.

Which secret a pipeline's CI job authenticates with is the PIPELINE's own answer (ci_secret_names, declared beside the workflow templates that read it), never a type name tested here: a pipeline publishing through OIDC trusted publishing needs no secret at all, and a local: true pipeline authenticates from the developer's own environment.

#secret_remedy

python
def secret_remedy(slug, secret)

The command that sets secret on slug from the local credential.

NPM_TOKEN has a documented one-liner that reads the token out of the developer's own ~/.npmrc; any other secret -- the Maven Central credentials, a GPG signing key, a hex.pm API key -- gets the same command with the value left for the operator to supply, since rlsbl knows no source for it and must not invent one.

#SecretVerdict

Result of probing one repository for the secrets its pipelines need.

#ok

python
def ok(self)

#evaluate_ci_secret_presence

python
def evaluate_ci_secret_presence(config, slug, *, probe=probe_repo_secret)

Every secret the configured CI publish pipelines need must exist.

More tools from this site

  • claudestream Drive Claude Code from Python: run it as a subprocess and read its output as typed events, with async and sync sessions, sandbox policies, and tools you define in Python
  • claudewheel A TUI Claude Code Launcher that lets you have more than one profile, manage sessions lifecycle, pick the exact CC version, model to use (even older unlisted ones), pick which GitHub account to use, etc.
  • dirstat Fast, single-binary directory statistics CLI: every file under a tree grouped by format, with counts, sizes, and lines of code, as a colored terminal table or as JSON
  • fastware A batteries-included ASGI framework: msgspec JSON, a managed Granian server, dependency injection, SSE, WebSockets, auth, and a test client
  • go-toml-edit Zero-dep TOML editing library for Go with comment preservation
  • howmuchleft The fastest Claude Code statusline: context window, 5-hour, and weekly limit usage as three customizable gradient bars, rendering in about 6 ms
  • orxtra
  • pgdesign
  • predraw Declarative rendering pipeline: describe a scene in JSON and get SVG, PNG and WebP out, with light and dark style tokens, reusable components and text converted to path outlines
  • reposummary Turn a git repository's history into a Markdown journal: pick a time window or revision range and get a readable digest of what changed, optionally narrated by an LLM
  • safegit git wrapper CLI that gives each commit its own temporary index and retries ref updates on conflict, so concurrent agents share one repository
  • saferm Command-line replacement for rm that archives every deletion with a mandatory reason and the context it ran in, so deleted files can be listed, inspected and restored
  • selfdoc Static Site Generator that builds a project's documentation site directly from its source code, so the docs can never drift from the code they describe, with SEO/AEO, first-class blog, search, and cross-project linking built in
  • strictcli
  • stricttest An always-on test-isolation floor: a pytest plugin and a Go env-hygiene module that make a test suite structurally unable to reach real credentials, the real HOME, the network, or the development repository.
  • wesktop A Python framework that turns an ASGI web app into a desktop application, serving it from a local Granian server and displaying it in a native OS window via pywebview
Search