I know that tje value of these variable are hidden on the pipeline‘s output.
But I could see those values with this trick below:
- step:
script:
- echo $VAR >> var.txt
artifacts:
- var.txt
You can see the value on var.txt file.
I want to use workspace variable for saving workspace access token, to reference it on a pipeline for accessing API, but because of this vulnerability I hesitate.