Rules
FP205 · undeclared-secret-ref
A reusable workflow reads a secret it does not declare, and some caller does not use `secrets: inherit`.
| Code | Name | Category | Default severity |
|---|---|---|---|
FP205 | undeclared-secret-ref | Secrets | 🔴 error |
Why it matters
Inside a called workflow only declared (or inherited) secrets exist. Reading anything else yields an empty string, so authentication steps fail late or, worse, fall back to anonymous access.
How to fix
Declare the secret under on.workflow_call.secrets and pass it from every caller, or use secrets: inherit.
Configure
Change the severity (or turn the rule off) in .github/flowpact/flowpact.config.yml, by code or by name:
rules:
FP205: off
# or: undeclared-secret-ref: errorExplain it in the terminal:
flowpact explain FP205