Repository navigation
Use scoped GitHub App tokens for authority maintenance - #350
Merged
Merged
Conversation
Co-Authored-By: Codex <noreply@openai.com>
Co-Authored-By: Codex <noreply@openai.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Authority maintenance currently depends on a stored personal access token that requires manual renewal. This change mints a short-lived GitHub App installation token for each manual maintenance run and scopes it to BinancePlatform. Plan requests read-only Environment access; apply requests Environment write access. Actions, repository Variables, and Metadata remain read-only.
The official token action is pinned to v3.2.0. Its declared inputs omit repository Variables, so the workflow supplies the supported parser environment key for
actions_variables. Token creation precedes authority materialization, the old stored PAT is no longer a fallback, and post-job revocation remains enabled. Trading execution, risk authority checks, and failure-stop behavior are unchanged.Validation: 50 focused authority/workflow tests passed; actionlint, changed-file ruff, diff checks, and the pinned official permission-parser mapping check passed. Independent permission review passed.
Activation is pending: the dedicated App has now been registered and its public client ID configured in binance-runtime. Installation is restricted to BinancePlatform and the private key is now configured in the protected environment. A separate read-only authentication check is included, but has not run remotely. Keep the existing PAT until real App authentication is verified. The protected environment currently allows only runtime-production; merging this PR to main alone does not adopt the change at that maintenance entry point or authorize any authority update.
The runtime-production tip currently differs from BINANCE_RUNTIME_WORKFLOW_SHA. Authentication migration must not advance that approved runtime pin or include unrelated runtime changes. Production adoption and retirement of the existing PAT remain pending.