Skip to content

H1 scriptworker-scripts redacted Taskcluster secret validation#1456

Draft
MathCarv wants to merge 2 commits into
mozilla-releng:masterfrom
MathCarv:h1-scriptworker-scripts-public-pr-redacted-secret-proof
Draft

H1 scriptworker-scripts redacted Taskcluster secret validation#1456
MathCarv wants to merge 2 commits into
mozilla-releng:masterfrom
MathCarv:h1-scriptworker-scripts-public-pr-redacted-secret-proof

Conversation

@MathCarv
Copy link
Copy Markdown

Controlled HackerOne validation PR.

This PR is intended to validate whether the public pull request Taskcluster role can access only redacted metadata for the configured secret scopes through taskclusterProxy.

Safety notes:

  • does not print full secret values
  • does not upload to third-party services
  • does not mutate Mozilla services
  • writes only redacted proof metadata to public/build/h1-scriptworker-scripts-redacted-secret-proof.json

This can be closed after validation.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant