spikersoft-infrastructure/gitea-act-runner/command-line-version.txt contains a live runner registration token in cleartext (found during the 2026-08-05 runner audit).
Per the secrets-in-openbao rule this should never be in git. Fix:
Rotate the token in Gitea > Site Administration > Actions > Runners (invalidate the committed one).
Remove the token from the file (or delete the file; the stack header already documents passing GITEA_RUNNER_REGISTRATION_TOKEN through the environment).
Store the replacement in OpenBao under secret/ci/spikersoft-infrastructure/... and note it in the provisioning script per the runbook.
Note: token is only needed for FRESH registrations — existing runners keep their .runner identity, so rotation does not disrupt the fleet.
`spikersoft-infrastructure/gitea-act-runner/command-line-version.txt` contains a live runner registration token in cleartext (found during the 2026-08-05 runner audit).
Per the secrets-in-openbao rule this should never be in git. Fix:
1. Rotate the token in Gitea > Site Administration > Actions > Runners (invalidate the committed one).
2. Remove the token from the file (or delete the file; the stack header already documents passing `GITEA_RUNNER_REGISTRATION_TOKEN` through the environment).
3. Store the replacement in OpenBao under `secret/ci/spikersoft-infrastructure/...` and note it in the provisioning script per the runbook.
Note: token is only needed for FRESH registrations — existing runners keep their `.runner` identity, so rotation does not disrupt the fleet.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
spikersoft-infrastructure/gitea-act-runner/command-line-version.txtcontains a live runner registration token in cleartext (found during the 2026-08-05 runner audit).Per the secrets-in-openbao rule this should never be in git. Fix:
GITEA_RUNNER_REGISTRATION_TOKENthrough the environment).secret/ci/spikersoft-infrastructure/...and note it in the provisioning script per the runbook.Note: token is only needed for FRESH registrations — existing runners keep their
.runneridentity, so rotation does not disrupt the fleet.