Skip to content

Pin tibdex/github-app-token action#31115

Merged
wadells merged 2 commits intomasterfrom
walt/pin-tibdex
Aug 30, 2023
Merged

Pin tibdex/github-app-token action#31115
wadells merged 2 commits intomasterfrom
walt/pin-tibdex

Conversation

@wadells
Copy link
Copy Markdown
Contributor

@wadells wadells commented Aug 28, 2023

This is a 3rd-party action with access to some moderately privileged GitHub Applications private tokens. If the tibdex user were compromised for any reason, we don't want to pick up an unexpected malicious update to v1.

I have a followup dependabot config, to ensure this stays current in a controlled fashion:

#31119

Also, we may move to github's in house https://github.com/actions/create-github-app-token once it is more mature -- but it is only a couple weeks old right now.

Corresponding Enterprise PR: https://github.com/gravitational/teleport.e/pull/2070

This is a 3rd-party action with access to some moderately privileged
GitHub Applications private tokens.  If tibdex were compromised
for any reason, we don't want to accidentally pick up an unexpected
malicious update to v1.
@wadells wadells requested a review from adaadb6 August 28, 2023 21:39
Copy link
Copy Markdown
Contributor

@adaadb6 adaadb6 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@wadells wadells requested a review from jentfoo August 28, 2023 22:19
@wadells wadells added this pull request to the merge queue Aug 29, 2023
@github-merge-queue github-merge-queue bot removed this pull request from the merge queue due to failed status checks Aug 29, 2023
@wadells wadells added this pull request to the merge queue Aug 30, 2023
@github-merge-queue github-merge-queue bot removed this pull request from the merge queue due to failed status checks Aug 30, 2023
@wadells wadells added this pull request to the merge queue Aug 30, 2023
@github-merge-queue github-merge-queue bot removed this pull request from the merge queue due to failed status checks Aug 30, 2023
@wadells wadells enabled auto-merge August 30, 2023 05:31
@wadells wadells added this pull request to the merge queue Aug 30, 2023
@github-merge-queue github-merge-queue bot removed this pull request from the merge queue due to failed status checks Aug 30, 2023
@wadells wadells added this pull request to the merge queue Aug 30, 2023
@github-merge-queue github-merge-queue bot removed this pull request from the merge queue due to failed status checks Aug 30, 2023
@wadells wadells added this pull request to the merge queue Aug 30, 2023
Merged via the queue into master with commit 8c20be8 Aug 30, 2023
@wadells wadells deleted the walt/pin-tibdex branch August 30, 2023 06:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants