SECURITY WARNING: Never run commands you don't understand. Always review code before execution. Use at your own risk.
CI/CD Added 11 February 2026

GitHub Actions: Secret not available in fork PRs

Secrets are not passed to workflows triggered by pull requests from forks for security reasons.

Quick fix

Read the commands before running them. Anything that restarts a service, deletes data or changes permissions should be tried on a non-production system first.

Quick fix
# Use pull_request_target instead (runs in base repo context)
on:
  pull_request_target:
    types: [opened, synchronize]
# Or skip secret-dependent steps in forks
- if: github.event.pull_request.head.repo.full_name == github.repository
  run: deploy.sh
  env:
    SECRET: ${{ secrets.MY_SECRET }}

How to diagnose CI/CD errors

CI failures that do not reproduce locally are almost always about environment, permissions or resource limits rather than about your code. CI runners have less memory than a laptop, a deliberately restricted token, a clean cache, and often a different CPU architecture. Treating a CI failure as a code bug before checking those four things wastes an enormous amount of time.

If the quick fix above does not resolve it, work through these steps. They apply to this whole class of error, not just to this one message, which is usually what saves the time.

  1. Re-run the job with debug logging enabled (ACTIONS_STEP_DEBUG=true in GitHub Actions, CI_DEBUG_TRACE in GitLab). The default log deliberately hides the most useful lines.
  2. Print the environment early: env | sort, node -v, free -m, df -h. Half of all "works on my machine" CI bugs are visible in that output.
  3. Check token permissions explicitly. GitHub's GITHUB_TOKEN defaults to read-only in many organisations and produces the misleading Resource not accessible by integration error.
  4. Remember that secrets are not available to workflows triggered by pull requests from forks. This is a security feature, not a misconfiguration.
  5. Reproduce locally in the same container image the runner uses, rather than on your host, before changing pipeline configuration.

Tools worth reaching for

  • ACTIONS_STEP_DEBUG
  • act (local Actions runner)
  • docker run <runner image>
  • free -m / df -h in-job

Authoritative references

Primary documentation for this error, worth reading before applying any fix in production.

docs.github.com

Related CI/CD errors

See all 18 CI/CD errors →

Browse other categories

Something missing or wrong?

This entry is maintained by hand. If the fix is out of date, incomplete, or you have a better one, email a correction and it will be reviewed.