fix(sops): encrypt from the temporary directory so the caller's .sops.yaml is never consulted #6
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "sops-config"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
The first migration of a real vault failed: sops found the repository's .sops.yaml and refused the plaintext temp file, which matched no creation rule. Encryption now runs with the private temp dir as cwd and an absolute target, so only the configured recipients apply. Regression test under a hostile .sops.yaml. Published as 2026.09.20.2.