# Environment variables not set anymore

**URL:** <https://travis-ci.community/t/environment-variables-not-set-anymore/5085>\
**Category:** Travis CI Discussions & Feedback\
**Tags:** env-vars\
**Created:** [September 13, 2019, 8:56am UTC](https://travis-ci.community/t/environment-variables-not-set-anymore/5085 "2019-09-13T08:56:22Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![apfelbox](https://sea1.discourse-cdn.com/flex015/user_avatar/travis-ci.community/apfelbox/32/2704_2.png) [@apfelbox](https://travis-ci.community/u/apfelbox)\
**Post date:** [September 13, 2019, 8:56am UTC](https://travis-ci.community/t/environment-variables-not-set-anymore/5085/1 "2019-09-13T08:56:22Z")

</div>

Hi!

I have this build: [https://travis-ci.org/Becklyn/mojave/builds/584466665](https://travis-ci.org/Becklyn/mojave/builds/584466665)

I have these env vars in the settings for this project:

 ![54](https://us1.discourse-cdn.com/flex015/uploads/travis_ci/original/2X/f/f8e69a6fd3b8916a6d5b2b93fbf57b44db2d6e0e.png)

But they don’t appear in the log anymore.  
Previously they were there with like

```
export BROWSERSTACK_KEY=[secure]

```

Now they don’t appear in the log anymore and “accidentally” our build is broken because of two missing env variables.

Is there something I need to change or configure differently?

Thanks!  
Jannik

---

<div class="post-metadata">

**Author:** ![BanzaiMan](https://sea1.discourse-cdn.com/flex015/user_avatar/travis-ci.community/banzaiman/32/67_2.png) [@BanzaiMan](https://travis-ci.community/u/BanzaiMan)\
**Post date:** [September 13, 2019, 11:58am UTC](https://travis-ci.community/t/environment-variables-not-set-anymore/5085/2 "2019-09-13T11:58:57Z")

</div>

The job you point to is a PR build (from a fork), so it doesn’t get to use the secrets for security reasons.

---

<div class="post-metadata">

**Author:** ![apfelbox](https://sea1.discourse-cdn.com/flex015/user_avatar/travis-ci.community/apfelbox/32/2704_2.png) [@apfelbox](https://travis-ci.community/u/apfelbox)\
**Post date:** [September 13, 2019, 12:29pm UTC](https://travis-ci.community/t/environment-variables-not-set-anymore/5085/3 "2019-09-13T12:29:50Z")

</div>

Okay, I understand that.

But does that mean, that PR builds (from a fork) can never have any build run, because we need BrowserStack for our builds?

That makes the OSS model for frontend code pretty broken?

---

<div class="post-metadata">

**Author:** ![native-api](https://sea1.discourse-cdn.com/flex015/user_avatar/travis-ci.community/native-api/32/430_2.png) [@native-api](https://travis-ci.community/u/native-api)\
**Post date:** [September 13, 2019, 4:37pm UTC](https://travis-ci.community/t/environment-variables-not-set-anymore/5085/4 "2019-09-13T16:37:40Z")

</div>

The code in PRs is untrusted because the contributor can change anything in it.  
So if you wish to provide a secret variable to a PR build, it’s effectively public – they can always find a way to expose its value.  
As such, there’s no point in making it a _secret_ variable then.
