镜像站点 · 本页由第三方 GitHub 只读镜像提供,非 GitHub 官方站点,不接受任何登录或凭据输入。前往 github.com
Skip to content

Migrate away from @nodejs-github-bot tokens. #1074

Description

@avivkeller

I think we should stop creating PATs associated with @nodejs-github-bot, and instead rely on the more secure alternative: GitHub App Tokens.

I've created a basic GitHub app that can be transferred into the org to replace @nodejs-github-bot.

WDYT?

Activity

  1. aduh95 commented on Jul 3, 2026

    @aduh95
    Contributor

    You probably need to include some details on why that would be a more secure alternative

  2. avivkeller commented on Jul 4, 2026

    @avivkeller
    MemberAuthor

    Compared to PATs, GitHub App Tokens are:

    • A PAT is scoped to whoever generated it, so the bot's access is effectively riding on that person's account. If that robot's account is ever compromised, the bot's credentials are entangled with them. A GitHub App is its own identity, owned by the org, so it keeps working and stays cleanly auditable as "the bot" independent of any one specific account.

    • GitHub App installation tokens expire after about 8 hours by default. Our PATs are issued for a year each time. If a credential ever leaks, the App-based approach caps the exposure window dramatically compared to a PAT.

    • A GitHub App is only installed on the specific repos it needs, with fine-grained permissions for just the actions it performs (e.g., commenting, labeling), rather than broad scopes like repo.

    FWIW We use app tokens in other places, e.g. https://github.com/apps/openjs-meetings-bot

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions