Skip to content

Douglas Liu

My feedback

3 results found

  1. 3 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    Douglas Liu supported this idea  · 
  2. 6 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    Douglas Liu supported this idea  · 
  3. 1 vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    An error occurred while saving the comment
    Douglas Liu commented  · 

    Why This Is Important / Benefits:

    1. Enhanced Security: This eliminates an entire class of credentials (the service account's PAT) that needs to be managed, rotated, and secured. Authentication would rely solely on the GitHub App's secure, short-lived tokens.

    2. Simplified Administration: It removes the operational overhead of creating, managing permissions for, and eventually off-boarding a separate user account in GitHub just for the CI/CD process.

    3. Clearer Attribution: A commit authored by Gearset App [ID: 123456] is a more precise and unambiguous audit trail than one authored by a generic svc-gearset user. It points directly to the application that performed the action.

    4. Future-Proofs Gearset's Architecture: Adopting this "application-first" identity model aligns Gearset with the direction modern enterprise security is heading. It would be a strong selling point for security-conscious customers.

    Here is an article related to this: https://josh-ops.com/posts/github-apps/#google_vignette

    Douglas Liu shared this idea  · 

Feedback and Knowledge Base