You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Personal access tokens cannot be limited to single projects. This is really insecure. A working workaround is to create bot users per project (this is generally a good idea). PR is on the way to clarify that.
Someone should however investigate whether it's possible to use alternative authentication methods of the GitHub API, e.g., something OAuth2 based. Those tokens can be limited to projects/organizations.
The text was updated successfully, but these errors were encountered:
TheAssassin
added a commit
to TheAssassin/uploadtool
that referenced
this issue
Jun 16, 2020
Personal access tokens cannot be limited to single projects. This is really insecure. A working workaround is to create bot users per project (this is generally a good idea). PR is on the way to clarify that.
Someone should however investigate whether it's possible to use alternative authentication methods of the GitHub API, e.g., something OAuth2 based. Those tokens can be limited to projects/organizations.
The text was updated successfully, but these errors were encountered: