GHA_SECRET_FORK cicd auth_error ai_generated partial

Error: Secret MY_ORG_SECRET is not set or is empty. Organization secrets are not available to forks.

ID: cicd/github-actions-secret-missing-org

Also available as: JSON · Markdown · 中文
80%Fix Rate
88%Confidence
1Evidence
2023-11-15First Seen

Version Compatibility

VersionStatusIntroducedDeprecatedNotes
GitHub Actions hosted runners (ubuntu-22.04, ubuntu-24.04) active
GitHub Enterprise Server 3.8+ active

Root Cause

GitHub Actions workflow attempts to access an organization-level secret from a forked repository, which is blocked by GitHub's security policy to prevent exposing secrets to external contributors.

generic

中文

GitHub Actions 工作流尝试从复刻仓库访问组织级机密,但 GitHub 安全策略禁止此操作,以防止机密泄露给外部贡献者。

Official Documentation

https://docs.github.com/en/actions/security-guides/using-secrets-in-github-actions#using-secrets-in-a-workflow

Workarounds

  1. 85% success Use `pull_request_target` trigger instead of `pull_request` to run the workflow in the context of the base repository, which has access to organization secrets. Example: `on: pull_request_target: types: [opened, synchronize]`
    Use `pull_request_target` trigger instead of `pull_request` to run the workflow in the context of the base repository, which has access to organization secrets. Example: `on: pull_request_target: types: [opened, synchronize]`
  2. 75% success Store the secret as a repository-level secret on the original repository and use a conditional step to skip it for forks: `if: github.event.pull_request.head.repo.fork == false`
    Store the secret as a repository-level secret on the original repository and use a conditional step to skip it for forks: `if: github.event.pull_request.head.repo.fork == false`

中文步骤

  1. Use `pull_request_target` trigger instead of `pull_request` to run the workflow in the context of the base repository, which has access to organization secrets. Example: `on: pull_request_target: types: [opened, synchronize]`
  2. Store the secret as a repository-level secret on the original repository and use a conditional step to skip it for forks: `if: github.event.pull_request.head.repo.fork == false`

Dead Ends

Common approaches that don't work:

  1. 85% fail

    Adding the secret as a repository-level secret on the fork does not work because the original workflow references the organization-level secret name and the fork cannot see it.

  2. 70% fail

    Changing the workflow to use `env:` instead of `secrets:` does not resolve the issue as the secret value is still required and must come from a context that the fork cannot access.