Skip to content

ci: GitHub App credentials from Bitwarden via scanoss/actions - #162

Merged
isasmendiagus merged 1 commit into
mainfrom
ci/bitwarden-app-credentials
Sep 16, 2026
Merged

isasmendiagus merged 1 commit into
mainfrom
ci/bitwarden-app-credentials

Conversation

@isasmendiagus

Copy link
Copy Markdown
Collaborator

The one step here that acted as the scanoss-automation App read the App's id and private key from the organisation-level GH_APP_ID / GH_APP_PRIVATE_KEY secrets. It now uses scanoss/actions/github-app-token@v1, which reads them from Bitwarden Secrets Manager and mints a one-hour token scoped to homebrew-dist. The only secret this repository needs is BWS_ACCESS_TOKEN (already set).

This workflow is not triggered by pull requests, so this PR's checks do not exercise it; the same layer is proven in scanoss/owlie#2 and in earnie and scanoss.api on main. Once merged, the organisation-level GH_APP_* pair has no consumer left and can be deleted.

🤖 Generated with Claude Code

The mint step read the App's id and private key from the organisation's
GH_APP_ID / GH_APP_PRIVATE_KEY secrets — one of several copies of the same
credential across the organisation. It now calls
scanoss/actions/github-app-token, which reads them from Bitwarden Secrets
Manager and mints a one-hour token scoped to homebrew-dist. The only secret this
repository needs is BWS_ACCESS_TOKEN.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown

SCANOSS SCAN Completed 🚀

  • Detected components: 3
  • Undeclared components: 0
  • Declared components: 3
  • Detected files: 192
  • Detected files undeclared: 0
  • Detected files declared: 192
  • Licenses detected: 2
  • Licenses detected with copyleft: 1
  • Policies: ✅ 1 pass (1 total)

View more details on SCANOSS Action Summary

@isasmendiagus
isasmendiagus merged commit e49f676 into main Sep 16, 2026
5 checks passed
@isasmendiagus
isasmendiagus deleted the ci/bitwarden-app-credentials branch September 16, 2026 12:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant