File tree Expand file tree Collapse file tree 1 file changed +0
-11
lines changed
Expand file tree Collapse file tree 1 file changed +0
-11
lines changed Original file line number Diff line number Diff line change @@ -88,44 +88,33 @@ jobs:
8888 EOF
8989 )
9090
91- echo "1"
92-
9391 # Mask AWS account IDs (12-digit numbers)
9492 echo "$PLAN_FULL" | grep -oE '[0-9]{12}' | while read -r account_id; do
9593 echo "::add-mask::$account_id"
9694 done
9795
98- echo "2"
99-
10096 # Mask Lambda invocation URLs
10197 echo "$PLAN_FULL" | grep -oE 'https://[a-zA-Z0-9.-]+\.lambda\.amazonaws\.com/[a-zA-Z0-9/._-]+' | while read -r lambda_url; do
10298 if [ -n "$lambda_url" ]; then
10399 echo "::add-mask::$lambda_url"
104100 fi
105101 done || echo "No Lambda URLs found to mask."
106102
107- echo "3"
108-
109103 # Mask API Gateway URLs (e.g., execute-api)
110104 echo "$PLAN_FULL" | grep -oE 'https://[a-zA-Z0-9.-]+\.execute-api\.[a-zA-Z0-9.-]+\.amazonaws\.com/[a-zA-Z0-9/._-]*' | while read -r api_url; do
111105 if [ -n "$api_url" ]; then
112106 echo "::add-mask::$api_url"
113107 fi
114108 done
115109
116- echo "4"
117-
118110 # Mask GitHub secrets
119111 echo "::add-mask::${{ secrets.AWS_ASSUME_ROLE }}"
120112 echo "::add-mask::${{ secrets.GITHUB_TOKEN }}"
121113
122- echo "5"
123114
124115 # Mask Terraform variables
125116 echo "::add-mask::${{ vars.TF_VARS_FILE }}"
126117
127- echo "6"
128-
129118 # Optionally redact sensitive strings in the PLAN_FULL variable
130119 PLAN_FULL=$(echo "$PLAN_FULL" | sed -E 's/[0-9]{12}/[REDACTED_AWS_ACCOUNT_ID]/g')
131120 PLAN_FULL=$(echo "$PLAN_FULL" | sed -E 's#https://[a-zA-Z0-9.-]+\.lambda\.amazonaws\.com/[a-zA-Z0-9/._-]+#[REDACTED_LAMBDA_URL]#g')
You can’t perform that action at this time.
0 commit comments