Use environment secrets for Crowdin actions#3753
Merged
Conversation
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## master #3753 +/- ##
=======================================
Coverage 81.31% 81.31%
=======================================
Files 620 620
Lines 39080 39080
Branches 6371 6352 -19
=======================================
Hits 31778 31778
- Misses 6317 6330 +13
+ Partials 985 972 -13 ☔ View full report in Codecov by Sentry. |
pmachapman
approved these changes
Mar 22, 2026
Collaborator
pmachapman
left a comment
There was a problem hiding this comment.
@pmachapman reviewed 2 files and all commit messages, and made 1 comment.
Reviewable status:complete! all files reviewed, all discussions resolved (waiting on Nateowami).
045a6c0 to
cc28415
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Zizmor has flagged our use of secrets outside an environment as not being a security best-practice, since it means the secrets are available to every action that runs. See https://docs.zizmor.sh/audits/#secrets-outside-env
Instead, secrets should be put in an environment (e.g. a "Crowdin" environment), and then workflows should state which environment they use.
What that means is that the security improvement isn't an update to a workflow; it's a change to how our secrets are stored in GitHub, to have better access control. However, doing that does necessitate an update to the workflows.
I've created a Crowdin environment in the repo settings, set
CROWDIN_PROJECT_IDandCROWDIN_API_KEY, and updated the workflow to reference them. After this is merged the old secrets should be removed from the repo's main secrets, so they're only available via the environment.This change is