You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Migrate away from @nodejs-github-bot tokens. #1074
A PAT is scoped to whoever generated it, so the bot's access is effectively riding on that person's account. If that robot's account is ever compromised, the bot's credentials are entangled with them. A GitHub App is its own identity, owned by the org, so it keeps working and stays cleanly auditable as "the bot" independent of any one specific account.
GitHub App installation tokens expire after about 8 hours by default. Our PATs are issued for a year each time. If a credential ever leaks, the App-based approach caps the exposure window dramatically compared to a PAT.
A GitHub App is only installed on the specific repos it needs, with fine-grained permissions for just the actions it performs (e.g., commenting, labeling), rather than broad scopes like repo.
I think we should stop creating PATs associated with @nodejs-github-bot, and instead rely on the more secure alternative: GitHub App Tokens.
I've created a basic GitHub app that can be transferred into the org to replace @nodejs-github-bot.
WDYT?