Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Feature request: Sync repo/org secrets to local .env for local development

Open
#598 0 comments 1 reaction 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
5/5
Estimated time
Over a week
Newbie friendliness
35/100
Issue type
Feature
Clarity
Mostly clear
Activity status
Quiet
Tech stack
github, github-actions, typescript, vscode

Research direction

No files or tests are named. Start by tracing the existing Secrets and Variables views and the GitHub login flow, then verify whether the proposed secret-value retrieval is supported safely. Done means the command previews scoped secret names, confirms before writing the workspace-root .env, and adds it to .gitignore when absent.

Written by the indexing model from the issue text.

Description

enhancement

Problem

Developers working locally must manually copy secrets into .env. Error-prone. Painful at scale. Drift between CI and local dev.

Extension already lists secret names in "Secrets" and "Variables" views. Cannot bridge to local env.

Proposed solution

Add command: "GitHub Actions: Pull Secrets to .env"

  1. Authenticate via existing GitHub login
  2. Fetch secret names for current repo + environments (same scope as Secrets view)
  3. Preview available secrets (names only)
  4. On confirm, fetch decrypted values (workflow-execution approach or new API endpoint)
  5. Write .env at workspace root (configurable)

Alternatives

Option Gap
Manual .env Current flow — time-consuming, drift-prone
act + secret file Need values already local. No help sourcing
GitHub Codespaces Auto-injects. But only for Codespaces, not local
gh extension Separate tool, extra auth context

Constraints

  • GitHub API does not expose secret plaintext (encrypted at rest by design)
  • Needs either: new API endpoint OR one-time workflow that echoes base64-encoded secret values
  • Solution parallel to how Codespaces injects secrets into the environment

Prior art

  • Codespaces: already auto-injects secrets into dev environment. This request brings parity to local dev.
  • #222 (500+ reactions): clear demand for improved secrets UX in extension

Success criteria

  • Open local repo in VS Code → run "Pull Secrets to .env"
  • GitHub auth (once) → see available secrets by scope
  • Confirm → .env written at workspace root
  • .env auto-.gitignore-d if absent
Dominant language
TypeScript
Stars
661
Forks
214
PR merge metrics
No merged PRs in 30d

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from github/vscode-github-actions

All issues in github/vscode-github-actions

Similar issues

More TypeScript issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.