Skip to content

Use GitHub App per repository for cases where the App needs content write access to a repository #2763

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
trask opened this issue May 19, 2025 · 0 comments
Assignees

Comments

@trask
Copy link
Member

trask commented May 19, 2025

Based on @CodeBlanch's #2127 (comment)

As we move towards using GitHub App for automation needs (https://github.com/open-telemetry/community/blob/main/assets.md#otelbot), sometimes the GitHub App needs content write access to a repository.

Instead of elevating the default otelbot GitHub App permissions, we should create a new App per repository that only has permissions scoped to that repository.

Trying this out first with opentelemetry-java-contrib: https://github.com/open-telemetry/opentelemetry-java-contrib/blob/11c3dda26b9ed5c91803f8e12e5411a272695cec/.github/workflows/auto-spotless-apply.yml#L40

@trask trask self-assigned this May 19, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant