Skip to main content

Forked pull requests receive secrets only when both project settings are on

Build forked pull requests and Pass secrets to builds from forked pull requests together let an external fork run with project secrets and contexts. A context limited to All members does not block that path.

A pull request from an external fork runs on CircleCI, and can receive project secrets, only when both of these project settings are enabled:

  • Build forked pull requests

  • Pass secrets to builds from forked pull requests

With both on, CircleCI runs the fork’s pull request and passes project secrets, contexts, and related credentials into that job.

Restricting a context to All members does not block this. While Pass secrets to builds from forked pull requests is on, the fork build is allowed to receive those secrets even though the author is not an organization member.

Turn it off

On each project that uses the secrets or the runner you care about:

  1. Turn Build forked pull requests off if you do not intend to run untrusted forks.

  2. Confirm Pass secrets to builds from forked pull requests is off.

  3. If a fork build already ran with the second setting on, rotate the values that were in scope (project environment variables, context secrets, and any cloud credentials that job could use).

Open-source projects that intentionally build forks should keep secrets out of that path: leave Pass secrets to builds from forked pull requests off, and do not attach contexts that hold credentials. Triggering a pipeline via the API is a separate feature and does not change these two checkboxes. See Trigger pipelines on forked pull requests with the API.

Did this answer your question?