summaryrefslogtreecommitdiff
path: root/data/deprecations/15-5-disable-file-type-var-expansion-ci-pipeline.yml
blob: 61f60ece3d43bf53a3974f261b59c651dfdbd5b2 (plain)
1
2
3
4
5
6
7
8
9
10
11
- title: "File Type variable expansion in `.gitlab-ci.yml`"  # (required) The name of the feature to be deprecated
  announcement_milestone: "15.5"  # (required) The milestone when this feature was first announced as deprecated.
  removal_milestone: "15.7"  # (required) The milestone when this feature is planned to be removed
  breaking_change: true  # (required) If this deprecation is a breaking change, set this value to true
  reporter: DarrenEastman  # (required) GitLab username of the person reporting the deprecation
  stage: Verify  # (required) String value of the stage that the feature was created in. e.g., Growth
  issue_url: https://gitlab.com/gitlab-org/gitlab/-/issues/29407  # (required) Link to the deprecation issue in GitLab
  body: |  # (required) Do not modify this line, instead modify the lines below.
    Previously, variables that referenced or applied alias file variables expanded the value of the `File` type variable. For example, the file contents. This behavior was incorrect because it did not comply with typical shell variable expansion rules. To leak secrets or sensitive information stored in `File` type variables, a user could run an $echo command with the variable as an input parameter.

    This breaking change fixes this issue but could disrupt user workflows that work around the behavior. With this change, job variable expansions that reference or apply alias file variables, expand to the file name or path of the `File` type variable, instead of its value, such as the file contents.