feat: remove SUPPORT_TOKEN and use create-github-app-token #1509
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Pull request template
There was a security breach on https://oi.empathy.co/ which exposed one of our GitHub tokens with access to the organisations private repositories. The token is
SUPPORT_TOKEN
, so now we have to remove this token from our workflows and replace it withcreate-github-app-token
action that generates tokens under demand.Documentation: https://developer.empathy.co/ci-cd/github-actions.html#interact-with-github-private-resources-from-a-github-workflow
Example: https://github.com/empathyco/platform-motive-helm-charts/blob/a44f5bf359ca59c8fbe5bdafc678bde4959a4491/.github/workflows/version-updater.yaml#L43-L61
Motivation and context
Type of change
What is the destination branch of this PR?
Main
How has this been tested?
Tests performed according to testing guidelines:
Checklist: