-
Notifications
You must be signed in to change notification settings - Fork 2
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open source? #1
Comments
Hi, I'm not sure what you mean by "it'll a huge hole"... The app does not have access to secrets, nor does it request such access. The reason the application code is not open-sourced is for proprietary reasons You can see what permissions the app requires when installing the application, and if you have any |
I think the goal of the conversation was more, this fixes a major hole in githubs feature set, we would like to review the code being allowed to manage runs on our proprietary repos. I think a source code audit for this kind of tool is a good practice just because of how powerful this tool will be and if a backdoor is injected the first warning would be a pipeline getting owned. Is this project for sale? I would willingly contribute financially as a private developer to get a peak at the source as well as sign NDA or whatever else, and my company or myself might be interested in purchasing the idea out right for a fair price. If commercial concerns are the worry here, lets talk business. |
What is the best way to get in touch with you directly? we are willing to make an offer to purchase this code. |
Hi @justinengland - you can message me on Twitter / LinkedIn |
I understand the concerns, what kind of audit are you expecting to perform? |
Hi @eladchen, I am also very interested in this. However, based on your App's docs, I am not quite sure it fits my use-case. I've described what I'm looking to achieve in this comment, can you please confirm if your App can do this or not? Based on the official docs and my initial experimentation, I don't understand how this can be done. To be clear: I'm looking to intercept and cancel all workflow runs, not just ones triggered by If you can confirm that your App is able to do what I described in my comment, I would potentially also be interested in a business discussion. Disclaimer: I'm speaking as a private developer now, not on behalf of my company. |
You can cancel any workflow run by setting the anyEvent rule. |
This app looks like it'll fix a huge hole in GitHub Actions and appears to open it up to many more exciting use cases, but given the nature of this app being used to protect our secrets, we need to be able to trust it!
How can you assure this is safe to use? Is it open source somewhere?
The text was updated successfully, but these errors were encountered: