From eacf0d6a873798753dbdfee48347b7b917f373ba Mon Sep 17 00:00:00 2001 From: neil Date: Sun, 12 Jul 2026 12:32:54 +0800 Subject: [PATCH] issue bot: tell reporters to redact secrets before posting logs Debug logs occasionally contain private keys or tokens (issue 6267); the code-side leak in the haproxy hook was fixed by #6268, this adds the missing warning to the auto-comment that asks for logs. --- .github/workflows/issue.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/issue.yml b/.github/workflows/issue.yml index f72a1f06..00e9ddc5 100644 --- a/.github/workflows/issue.yml +++ b/.github/workflows/issue.yml @@ -82,5 +82,5 @@ jobs: issue_number: issue.number, owner: context.repo.owner, repo: context.repo.repo, - body: "Please upgrade to the latest code and try again first. Maybe it's already fixed. ```acme.sh --upgrade``` If it's still not working, please provide the log with `--debug 2`, otherwise, nobody can help you." + body: "Please upgrade to the latest code and try again first. Maybe it's already fixed. ```acme.sh --upgrade``` If it's still not working, please provide the log with `--debug 2`, otherwise, nobody can help you. Before posting the log, review it and REDACT any secrets: private keys (`-----BEGIN ... PRIVATE KEY-----` blocks), API tokens and passwords." }) \ No newline at end of file