Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security review of 3rd party services #1166

Open
9 tasks
mtrezza opened this issue Apr 28, 2022 · 7 comments
Open
9 tasks

Security review of 3rd party services #1166

mtrezza opened this issue Apr 28, 2022 · 7 comments
Labels
type:meta Non-code issue

Comments

@mtrezza
Copy link
Member

mtrezza commented Apr 28, 2022

We are doing our annual security review of 3rd party services. The goal is to remove permissions of services that are no longer used in this repository's CI workflow.

Services that need to be reviewed:

  • Travis CI for Open Source
  • Coveralls
  • StyleCI
  • Travis CI
  • AppVeyor
  • AppVeyor CI
  • CircleCI
  • Code Climate
  • Packagist
@mtrezza mtrezza added the type:meta Non-code issue label Apr 28, 2022
@mtrezza
Copy link
Member Author

mtrezza commented Apr 28, 2022

@parse-community/android-sdk-review if someone could take a look and confirm whether we can remove all the services above, that would be great

@azlekov
Copy link
Contributor

azlekov commented May 31, 2022

@mtrezza I'm pretty sure all of them can be removed

@mtrezza
Copy link
Member Author

mtrezza commented May 31, 2022

I would say so too. Haven't found any indication so far that any of these are used here.

@Jawnnypoo
Copy link
Member

Coveralls is used to post on PRs, for example:

#1163 (comment)

Up to you guys on if you think this is useful to keep around. The rest seem inactive to me.

@azlekov
Copy link
Contributor

azlekov commented Jun 1, 2022

Codecov == Coveralls?

@Jawnnypoo
Copy link
Member

I believe so

@mtrezza
Copy link
Member Author

mtrezza commented Jun 2, 2022

These are 2 different services.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
type:meta Non-code issue
Projects
None yet
Development

No branches or pull requests

3 participants