Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

feat: remove SUPPORT_TOKEN and use create-github-app-token #1509

Merged
merged 1 commit into from
Jun 10, 2024

Conversation

lauramargar
Copy link
Contributor

@lauramargar lauramargar commented Jun 10, 2024

Pull request template

There was a security breach on https://oi.empathy.co/ which exposed one of our GitHub tokens with access to the organisations private repositories. The token is SUPPORT_TOKEN, so now we have to remove this token from our workflows and replace it with create-github-app-token action that generates tokens under demand.

Documentation: https://developer.empathy.co/ci-cd/github-actions.html#interact-with-github-private-resources-from-a-github-workflow

Example: https://github.com/empathyco/platform-motive-helm-charts/blob/a44f5bf359ca59c8fbe5bdafc678bde4959a4491/.github/workflows/version-updater.yaml#L43-L61

Motivation and context

  • Dependencies. If any, specify:
  • Open issue. If applicable, link:

Type of change

  • Bug fix (non-breaking change that fixes an issue)
  • New feature (non-breaking change that adds functionality)
  • Breaking change (fix or feature that causes existing functionality to not work as expected)
  • Change requires a documentation update

What is the destination branch of this PR?

  • Main
  • Other. Specify:

How has this been tested?

Tests performed according to testing guidelines:

Checklist:

  • My code follows the style guidelines of this project.
  • I have performed a self-review on my own code.
  • I have commented my code, particularly in hard-to-understand areas.
  • I have made corresponding changes to the documentation.
  • My changes generate no new warnings.
  • I have added tests that prove my fix is effective or that my feature works.
  • New and existing unit tests pass locally with my changes.

@lauramargar lauramargar requested a review from a team as a code owner June 10, 2024 08:57
@diegopf diegopf merged commit a03fe4b into main Jun 10, 2024
4 checks passed
@diegopf diegopf deleted the feature/remove-SUPPORT_TOKEN branch June 10, 2024 09:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants