Stand-in credential values for gh, AWS and gcloud are defined, with substitution rules unsettled.
A table of placeholder credential env vars is primed at startup, but what decides substitution is not resolved in this code.
What's wrong with this entry?
A table now maps each of these command-line tools to the credential environment variables it reads and to stand-in values for them, covering GH_TOKEN and GITHUB_TOKEN, the full AWS set including container credential URIs, and the Google Cloud SDK token and application default credentials path. A startup step primes these and logs without failing if it cannot. What decides when the placeholders are substituted is not settled by the code that defines them.
AWS_CONTAINER_CREDENTIALS_RELATIVE_URI
Strings lifted out of the shipped bundle, so the claim above can be checked against them.
Related
Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.
-
v2.1.236
macOS sandbox re-applies read and delete denials inside writable folders
Both mention sandbox
-
v2.1.236
Sandbox proxy no longer writes to sockets that have gone away
Both mention sandbox
-
v2.1.236
IPv6 hosts through the proxy
Both mention sandbox