You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Not much info can be leaked apart from commit messages, issues & merge requests, but I agree.
This is planned for the future. May use Gitlab oAuth as well... not sure.
Commit give infos about new features/security fixes etc... Then it's a security issue to not support the repo token.
Adding Access token would be cool too, but a guy with read-only access shouldn't be able to configure the repo, this is why i'd prefer to use the repo token.
Currently anybody can configure any repo on any discord, this is a security issue.
Requiring the repo secret token is the best way to fix it and avoid infos leak through your bot.
The text was updated successfully, but these errors were encountered: