Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Pin tibdex/github-app-token action #31115

Merged
merged 2 commits into from
Aug 30, 2023
Merged

Pin tibdex/github-app-token action #31115

merged 2 commits into from
Aug 30, 2023

Conversation

wadells
Copy link
Contributor

@wadells wadells commented Aug 28, 2023

This is a 3rd-party action with access to some moderately privileged GitHub Applications private tokens. If the tibdex user were compromised for any reason, we don't want to pick up an unexpected malicious update to v1.

I have a followup dependabot config, to ensure this stays current in a controlled fashion:

#31119

Also, we may move to github's in house https://github.com/actions/create-github-app-token once it is more mature -- but it is only a couple weeks old right now.

Corresponding Enterprise PR: https://github.com/gravitational/teleport.e/pull/2070

This is a 3rd-party action with access to some moderately privileged
GitHub Applications private tokens.  If tibdex were compromised
for any reason, we don't want to accidentally pick up an unexpected
malicious update to v1.
@wadells wadells requested a review from adaadb6 August 28, 2023 21:39
Copy link
Contributor

@adaadb6 adaadb6 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@wadells wadells requested a review from jentfoo August 28, 2023 22:19
@wadells wadells added this pull request to the merge queue Aug 29, 2023
@github-merge-queue github-merge-queue bot removed this pull request from the merge queue due to failed status checks Aug 29, 2023
@wadells wadells added this pull request to the merge queue Aug 30, 2023
@github-merge-queue github-merge-queue bot removed this pull request from the merge queue due to failed status checks Aug 30, 2023
@wadells wadells added this pull request to the merge queue Aug 30, 2023
@github-merge-queue github-merge-queue bot removed this pull request from the merge queue due to failed status checks Aug 30, 2023
@wadells wadells enabled auto-merge August 30, 2023 05:31
@wadells wadells added this pull request to the merge queue Aug 30, 2023
@github-merge-queue github-merge-queue bot removed this pull request from the merge queue due to failed status checks Aug 30, 2023
@wadells wadells added this pull request to the merge queue Aug 30, 2023
@github-merge-queue github-merge-queue bot removed this pull request from the merge queue due to failed status checks Aug 30, 2023
@wadells wadells added this pull request to the merge queue Aug 30, 2023
Merged via the queue into master with commit 8c20be8 Aug 30, 2023
@wadells wadells deleted the walt/pin-tibdex branch August 30, 2023 06:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants