webhook add reads the secret from stdin; runner docs name real attachments !510

merged merged by cmc on 2026-09-29 00:19 UTC · krz/gitbay:webhook-secret-stdin into main

Discussion

cmc
  • webhook add <repo> <url> --secret - reads the signing secret from stdin (ReadsStdin); a literal --secret <value> is refused with exit 2 and a message saying to pipe it. The CLI forwards stdin for --secret -. API wiki page, e2e test and CHANGELOG. Closes #284.
  • The runner drop-in's comment lists the repositories the runner is attached to, and the Admin page's runner-validation procedure attaches a scratch repository and adds -repos for the run instead of naming cmc/ci-smoke. Closes #287.

Scripts that pass --secret <value> must change to printf %s SECRET | gitbay webhook add ... --secret -.