diff --git a/dist/index.js b/dist/index.js index 96dbde9..ddf74c1 100644 --- a/dist/index.js +++ b/dist/index.js @@ -181,21 +181,25 @@ async function assumeRole(params) { } function exportCredentials(params){ - // Configure the AWS CLI and AWS SDKs using environment variables + // Configure the AWS CLI and AWS SDKs using environment variables and set them as secrets. + // Setting the credentials as secrets masks them in Github Actions logs const {accessKeyId, secretAccessKey, sessionToken} = params; // AWS_ACCESS_KEY_ID: // Specifies an AWS access key associated with an IAM user or role core.exportVariable('AWS_ACCESS_KEY_ID', accessKeyId); + core.setSecret('AWS_ACCESS_KEY_ID', accessKeyId); // AWS_SECRET_ACCESS_KEY: // Specifies the secret key associated with the access key. This is essentially the "password" for the access key. core.exportVariable('AWS_SECRET_ACCESS_KEY', secretAccessKey); + core.setSecret('AWS_SECRET_ACCESS_KEY', secretAccessKey); // AWS_SESSION_TOKEN: // Specifies the session token value that is required if you are using temporary security credentials. if (sessionToken) { core.exportVariable('AWS_SESSION_TOKEN', sessionToken); + core.setSecret('AWS_SESSION_TOKEN', sessionToken); } }