Skip to content

v2.75.0: GitHub tokens no longer sit in plain text on disk, and connected repos can use a GitHub App

Choose a tag to compare

@gitayg gitayg released this 13 Sep 13:18
· 34 commits to main since this release

Security

  • Deploys, AppStudio and the builder used to clone with the GitHub token inside the git URL. git saved that URL in each release directory and workspace, so every personal access token and the managed-app service-account token was left in plain text on disk. The builder workspace is also mounted into the AI container, which could read it. Tokens now reach git only through its environment and are never written to disk.
  • On boot, AppCrane removes those saved credentials from existing release directories, AppStudio job directories and builder workspaces. Only the credential part of the remote URL is removed; app data and volumes are never touched.
  • Rotate your stored GitHub tokens after upgrading: the cleanup removes the copies on disk but cannot undo the exposure.
  • App list and app detail responses no longer include encrypted credential columns (GitHub token, Claude credentials). The dashboard only needs the "has token" flags.

GitHub App for connected repos

  • A platform admin can create this instance's own GitHub App from Settings > GitHub. It asks only for read access to code, metadata and pull requests.
  • Attach a connected app to it from the app list ("gh app"). Deploys, the pre-deploy commit check, the pull-request poller and check-for-updates then use a one-hour token limited to that repo instead of the stored personal access token.
  • If an attached app cannot get a token, the operation fails with the reason. It never falls back to the stored token.
  • Apps that are not attached keep working exactly as before.
  • Not yet covered by the App: AppStudio coding and pull requests, releases, snapshots and the issues mirror. Register on GitHub is refused for attached apps, because the App is read-only.

Dashboard

  • Each app in the list shows where its code comes from: Crane-hosted, Managed (GitHub), GitHub App, GitHub token or Public GitHub.
  • Signing in to the dashboard with an API key no longer signs you out on every page load.