fix(sops): encrypt from the temporary directory so the caller's .sops.yaml is never consulted #6

Merged
beddari merged 1 commit from sops-config into main 2026-09-20 17:27:46 +00:00
Owner

The first migration of a real vault failed: sops found the repository's .sops.yaml and refused the plaintext temp file, which matched no creation rule. Encryption now runs with the private temp dir as cwd and an absolute target, so only the configured recipients apply. Regression test under a hostile .sops.yaml. Published as 2026.09.20.2.

The first migration of a real vault failed: sops found the repository's .sops.yaml and refused the plaintext temp file, which matched no creation rule. Encryption now runs with the private temp dir as cwd and an absolute target, so only the configured recipients apply. Regression test under a hostile .sops.yaml. Published as 2026.09.20.2.
sops looks for .sops.yaml upward from its working directory and, having
found one, refuses an input file that matches none of its creation
rules, which the plaintext temporary file never does. Encryption now
runs with the private temporary directory as its working directory and
an absolute target, so the configured recipients are the only ones and a
repository's .sops.yaml is irrelevant to the vault. Regression test
under a .sops.yaml whose rules match nothing. 2026.09.20.2.
beddari deleted branch sops-config 2026-09-20 17:27:46 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
dataverket/swamp-extensions!6
No description provided.