@@ -54,12 +54,12 @@ files=$(find "$secrets_directory" -name "*.gpg")
54
54
# secret.
55
55
for encrypted_file in $files ; do
56
56
echo " Decrypting $encrypted_file "
57
- scripts_dir=$( dirname $0 )
57
+ scripts_dir=$( dirname " $0 " )
58
58
# The decrypted file's path will match the encrypted file's path, minus the
59
59
# trailing `.gpg` extension.
60
60
decrypted_file=${encrypted_file% .* }
61
61
source " $scripts_dir /decrypt_gha_secret.sh" \
62
- $encrypted_file $decrypted_file $current_secret_key
62
+ " $encrypted_file " " $decrypted_file " " $current_secret_key "
63
63
if [ ! -f " $decrypted_file " ]; then
64
64
echo " Error: The file could not be decrypted: $encrypted_file "
65
65
exit 1
@@ -68,16 +68,16 @@ for encrypted_file in $files; do
68
68
# Remove current encrypted file or else re-encryption will fail due to the
69
69
# gpg file already existing. The below script invocation will re-encrypt
70
70
# the file to the `encrypted_file` path.
71
- rm $encrypted_file
71
+ rm " $encrypted_file "
72
72
73
73
echo " Encrypting with new secret to $encrypted_file "
74
74
75
- source " $scripts_dir /encrypt_gha_secret.sh" $decrypted_file $new_secret_key
75
+ source " $scripts_dir /encrypt_gha_secret.sh" " $decrypted_file " " $new_secret_key "
76
76
if [ ! -f " $encrypted_file " ]; then
77
77
echo " Error: The file could not be encrypted: $decrypted_file "
78
78
exit 1
79
79
fi
80
80
81
81
# Cleanup the decrpted file now that it's been re-encrypted.
82
- rm $decrypted_file
82
+ rm " $decrypted_file "
83
83
done
0 commit comments