hermes - 💡(How to fix) Fix [SECURITY] VERCEL_DEPLOY_HOOK secret exposed in shell run: block (deploy-site.yml)

Official PRs (…)
ON THIS PAGE

Recommended Tools

×6

Utilities matched from this issue’s tags and category — try them while you read without losing context.

GitHub issue graph ai analysis

Paste a GitHub issue URL. We fetch that issue, discover linked issues from bodies/comments/timeline, collect linked pull requests, and produce a structured English report.

The report is written in English Markdown for sharing and archival.

Helpful · Quick feedback

Loading…

Fix Action

Fix

Move to env: block:

- name: Deploy
  env:
    VERCEL_DEPLOY_HOOK: ${{ secrets.VERCEL_DEPLOY_HOOK }}
  run: curl -X POST "$VERCEL_DEPLOY_HOOK"

Code Example

- name: Deploy
  env:
    VERCEL_DEPLOY_HOOK: ${{ secrets.VERCEL_DEPLOY_HOOK }}
  run: curl -X POST "$VERCEL_DEPLOY_HOOK"
RAW_BUFFERClick to expand / collapse

Security Finding — /cso Audit 2026-05-11

Severity: MEDIUM | Confidence: 8/10 | Status: VERIFIED File: .github/workflows/deploy-site.yml ~line 29

What

VERCEL_DEPLOY_HOOK is expanded directly in a shell run: block via ${{ secrets.VERCEL_DEPLOY_HOOK }}.

Impact

If debug logging is enabled, the deploy hook URL (containing a token) could leak to workflow logs. Leaked token = unauthorized deployments.

Fix

Move to env: block:

- name: Deploy
  env:
    VERCEL_DEPLOY_HOOK: ${{ secrets.VERCEL_DEPLOY_HOOK }}
  run: curl -X POST "$VERCEL_DEPLOY_HOOK"

Immediate Actions

  1. Rotate the Vercel deploy hook
  2. Review deploy logs for unauthorized deployments

Found by /cso automated security audit

Vote matrix · Quick signals

Works
Did the solution work? Tap to confirm.
Easy Fix
Was it a quick fix?
Time Saver
Did it save you time?
Blocking
Was it severely blocking?
Common Issue
Are others likely hitting this too?
Flaky / Intermittent
Is it intermittent?
Verified / Reproducible
Can you reproduce it reliably?
Loading…

Still need to ship something?

×6

Another batch ranked right after the header list — different links, same matching logic.

Back to top recommendations

TRENDING