Skip to content

Adopt GitHub App authentication for protected Binance maintenance - #351

Merged
Pigbibi merged 1 commit into
runtime-productionfrom
fix/binance-authority-app-adoption
Oct 7, 2026
Merged

Pigbibi merged 1 commit into
runtime-productionfrom
fix/binance-authority-app-adoption

Conversation

@Pigbibi

@Pigbibi Pigbibi commented Oct 7, 2026

Copy link
Copy Markdown
Collaborator

The protected binance-runtime environment permits only runtime-production, so the App authentication merged to main has not been adopted by the maintenance entry point. This adopts only the five maintenance files from #350 onto runtime-production and extends the isolated authentication check to serially mint the read/write Environment permission variants used by plan/apply. Both checks perform GET requests only; they do not read risk-authority JSON, update configuration, or dispatch trading.

The runtime workflow, runtime source, release pin, approved workflow pin, and trading controls are unchanged. The existing difference between runtime-production and BINANCE_RUNTIME_WORKFLOW_SHA remains a separate release issue and is not approved by this PR. Keep the old maintenance PAT until the deployed App authentication check succeeds and its token revocation is confirmed.

Validation: 51 focused authority/workflow tests passed; actionlint, ruff, five-file scope checks, credential-pattern checks, and diff checks passed. Independent permissions review passed. Real hosted authentication is pending until adoption.

…anch

Co-Authored-By: Codex <noreply@openai.com>
@Pigbibi
Pigbibi merged commit e5f3caa into runtime-production Oct 7, 2026
1 check passed
@Pigbibi
Pigbibi deleted the fix/binance-authority-app-adoption branch October 7, 2026 17:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant