GHA_SECRET_FORK
cicd
auth_error
ai_generated
partial
Error: Secret MY_ORG_SECRET is not set or is empty. Organization secrets are not available to forks.
ID: cicd/github-actions-secret-missing-org
80%Fix Rate
88%Confidence
1Evidence
2023-11-15First Seen
Version Compatibility
| Version | Status | Introduced | Deprecated | Notes |
|---|---|---|---|---|
| GitHub Actions hosted runners (ubuntu-22.04, ubuntu-24.04) | active | — | — | — |
| GitHub Enterprise Server 3.8+ | active | — | — | — |
Root Cause
GitHub Actions workflow attempts to access an organization-level secret from a forked repository, which is blocked by GitHub's security policy to prevent exposing secrets to external contributors.
generic中文
GitHub Actions 工作流尝试从复刻仓库访问组织级机密,但 GitHub 安全策略禁止此操作,以防止机密泄露给外部贡献者。
Official Documentation
https://docs.github.com/en/actions/security-guides/using-secrets-in-github-actions#using-secrets-in-a-workflowWorkarounds
-
85% success Use `pull_request_target` trigger instead of `pull_request` to run the workflow in the context of the base repository, which has access to organization secrets. Example: `on: pull_request_target: types: [opened, synchronize]`
Use `pull_request_target` trigger instead of `pull_request` to run the workflow in the context of the base repository, which has access to organization secrets. Example: `on: pull_request_target: types: [opened, synchronize]`
-
75% success Store the secret as a repository-level secret on the original repository and use a conditional step to skip it for forks: `if: github.event.pull_request.head.repo.fork == false`
Store the secret as a repository-level secret on the original repository and use a conditional step to skip it for forks: `if: github.event.pull_request.head.repo.fork == false`
中文步骤
Use `pull_request_target` trigger instead of `pull_request` to run the workflow in the context of the base repository, which has access to organization secrets. Example: `on: pull_request_target: types: [opened, synchronize]`
Store the secret as a repository-level secret on the original repository and use a conditional step to skip it for forks: `if: github.event.pull_request.head.repo.fork == false`
Dead Ends
Common approaches that don't work:
-
85% fail
Adding the secret as a repository-level secret on the fork does not work because the original workflow references the organization-level secret name and the fork cannot see it.
-
70% fail
Changing the workflow to use `env:` instead of `secrets:` does not resolve the issue as the secret value is still required and must come from a context that the fork cannot access.