diff --git a/__tests__/buildx/build.test.ts b/__tests__/buildx/build.test.ts index 66593664..c7b51e34 100644 --- a/__tests__/buildx/build.test.ts +++ b/__tests__/buildx/build.test.ts @@ -348,10 +348,11 @@ describe('resolveAttestationAttrs', () => { describe('hasGitAuthTokenSecret', () => { // prettier-ignore test.each([ - [['A_SECRET=abcdef0123456789'], false], - [['GIT_AUTH_TOKEN=abcdefghijklmno=0123456789'], true], - ])('given %p secret', async (kvp: Array, expected: boolean) => { - expect(Build.hasGitAuthTokenSecret(kvp)).toBe(expected); + [['A_SECRET=abcdef0123456789'], undefined, false], + [['GIT_AUTH_TOKEN=abcdefghijklmno=0123456789'], undefined, true], + [['GIT_AUTH_TOKEN.github.com=abcdefghijklmno=0123456789'], 'github.com', true], + ])('given %p secret', async (kvp: Array, domain: string | undefined, expected: boolean) => { + expect(Build.hasGitAuthTokenSecret(kvp, domain)).toBe(expected); }); }); diff --git a/src/buildx/build.ts b/src/buildx/build.ts index 2db3aaee..4de6ceaf 100644 --- a/src/buildx/build.ts +++ b/src/buildx/build.ts @@ -310,9 +310,11 @@ export class Build { return res.join(','); } - public static hasGitAuthTokenSecret(secrets: string[]): boolean { + public static hasGitAuthTokenSecret(secrets: string[], domain?: string): boolean { for (const secret of secrets) { - if (secret.startsWith('GIT_AUTH_TOKEN=')) { + if (domain && secret.startsWith(`GIT_AUTH_TOKEN.${domain}=`)) { + return true; + } else if (secret.startsWith('GIT_AUTH_TOKEN=')) { return true; } }