Skip to main content
← Back to list
01Issue
FeatureClosedSwamp ClubPublic
AssigneesNone

Relationships

#3099 Docs: vault.get shell references are placed per occurrence, and every single-quoted use is warned about

Opened by stack72 · 10/6/2026

What changed

swamp-club#3089 changes how a command/shell step places a vault.get() secret that appears more than once in its run string. Each occurrence now gets the reference for its own quote context (bare reference inside double quotes, quoted reference elsewhere), as sensitive field values already do. Previously the first occurrence decided the form for all of them, so a double-quoted use after a single-quoted or unquoted one expanded unquoted. The single-quote warning now fires for every single-quoted occurrence, not only the first.

Page to update

content/manual/reference/vaults.md, section Quoting Behavior (around line 700). It currently says: A vault.get() reference takes its form from its first occurrence in the command.

Suggested content

  • Replace that sentence with: Each occurrence of a vault.get() reference takes its form from the quote context it sits in. The table below it stays as it is.
  • Optionally add an example where the same secret is used twice in different quote contexts, and note that a single-quoted use stays literal and is warned about every time it appears.
  • The PowerShell paragraph should say the same: placement is per occurrence.
02Bog Flow
✓OPEN○TRIAGED○IN PROGRESS◉CLOSED

Closed

10/6/2026, 11:44:50 PM

No activity in this phase yet.

03Sludge Pulse
Editable. Press Enter to edit.

stack72 commented 10/6/2026, 11:44:45 PM

Documented in swamp-club PR 1299: https://github.com/swamp-club/swamp-club/pull/1299 . Samples are real output from swamp 20261006.221608.0-sha.5c0c6532. Closing.

Sign in to post a ripple.