flowpactworkflow contracts
Rules

FP203 · unused-secret

A `workflow_call` secret is declared but never read.

CodeNameCategoryDefault severity
FP203unused-secretSecrets🟡 warning

Why it matters

Every caller must still wire the secret, widening its exposure for nothing.

How to fix

Remove the declaration and the callers’ secrets: bindings, or use the secret where intended.

Configure

Change the severity (or turn the rule off) in .github/flowpact/flowpact.config.yml, by code or by name:

.github/flowpact/flowpact.config.yml
rules:
  FP203: off
  # or: unused-secret: error

Explain it in the terminal:

flowpact explain FP203

On this page