flowpactworkflow contracts
Rules

FP204 · secrets-inherit

`secrets: inherit` hands every repository secret to the callee; flowpact lists what is actually needed.

CodeNameCategoryDefault severity
FP204secrets-inheritSecrets🔵 info

Why it matters

Inherit makes the secret flow invisible: nobody can tell from the caller which secrets reach which job, and every nested workflow gets all of them.

How to fix

Replace secrets: inherit with an explicit secrets: mapping of the secrets listed in the message.

Example

uses: ./.github/workflows/deploy.yml
secrets: inherit

Configure

Change the severity (or turn the rule off) in .github/flowpact/flowpact.config.yml, by code or by name:

.github/flowpact/flowpact.config.yml
rules:
  FP204: off
  # or: secrets-inherit: error

Explain it in the terminal:

flowpact explain FP204

On this page