Security
How do I pass secrets into a Docker build?
Quick answer
Use BuildKit build secrets with --secret, never ARG or ENV.
The detail that matters
ARG values persist in the image history and are trivially recoverable. Build secrets are mounted only for the RUN that uses them.
Your next build could be twice as fast, at half the price
Start free. Migrating away is the same one line, and we publish that diff too.
Related
Are snapshot runners safe for public repositories?Only if snapshots are taken from trusted branches and never from fork pull requests.How do I generate an SBOM?Enable buildx's sbom: true output, or run syft against the built image.How do I attach build provenance?Use actions/attest-build-provenance, or buildx's provenance: true attestation.Are GitHub Actions runners secure?GitHub-hosted and reputable managed runners are ephemeral single-use VMs, which is the right isolation model.