fix: drop empty env entries instead of keeping explicit empty values (#688)
* fix: drop empty env entries instead of keeping explicit empty values NAME= entries are now dropped from the environment entirely. Hosted builders pass every variable as NAME=value including empties, and BuildKit cannot mount an empty env secret, so keeping empty variables produced plans referencing secrets the builder never registers (failed to solve: secret X not found). Bare NAME entries still inherit from the process environment for local CLI use. NAME= must never inherit: variable names are user-controlled and would read values out of the build daemon's environment. * trim comments * docs: reword empty-value comment to describe behavior only * single-line comment
J
Jake Runzer committed
2f38527efef9ca28231abb58289c4737efd8f9fa
Parent: 34e4066
Committed by GitHub <noreply@github.com>
on 8/11/2026, 7:34:15 PM