Hello Bitbucket Community,
I’m currently evaluating whether to use Bitbucket’s global runners or opt for self-hosted runners for my CI/CD workflows. My pipeline involves several steps where sensitive secrets (such as API keys, tokens, and service account credentials) are exported and utilized during the build and deployment process.
My key concern is around the security of these secrets when using Bitbucket’s global runners: