Security
Can the runner platform see my secrets?
Quick answer
Secrets are decrypted in the runner's memory to be used, so any runner platform technically could.
The detail that matters
This is why isolation and audit matter. Prefer OIDC over stored secrets so there is less to expose.
Your next build could be twice as fast, at half the price
Start free. Migrating away is the same one line, and we publish that diff too.
Related
Are snapshot runners safe for public repositories?Only if snapshots are taken from trusted branches and never from fork pull requests.How do I generate an SBOM?Enable buildx's sbom: true output, or run syft against the built image.How do I attach build provenance?Use actions/attest-build-provenance, or buildx's provenance: true attestation.How do I pass secrets into a Docker build?Use BuildKit build secrets with --secret, never ARG or ENV.