Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix(resolve-repositories): limit to user owned repos #44

Merged
merged 1 commit into from
May 26, 2021
Merged

fix(resolve-repositories): limit to user owned repos #44

merged 1 commit into from
May 26, 2021

Conversation

stoe
Copy link
Contributor

@stoe stoe commented May 26, 2021

πŸ“ Summary

  • Running @octoherd/cli v3.3.2 (@octoherd/octokit v2.3.1, Node.js: v14.16.0, darwin x64)
  • Limit to affiliation: "owner" for the "GET /user/repos" route call.

β›± Motivation and Context

When using --octoherd-repos "user/*" with a repo scoped Personal Access Token (PAT) resolveRepositories.js would find all repositories the user has access to, not only the ones owned by that user under their account.

πŸ“Š How Has This Been Tested?

Modifying a local script with these changes:

node cli.js \
  --octoherd-token "0123456789012345678901234567890123456789" \
  --octoherd-repos "stoe/*"

Before

before

After

after

Copy link
Member

@gr2m gr2m left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Great catch, thanks a lot for the PR!

@gr2m gr2m merged commit 31d1a8a into octoherd:main May 26, 2021
@github-actions
Copy link

πŸŽ‰ This PR is included in version 3.3.3 πŸŽ‰

The release is available on:

Your semantic-release bot πŸ“¦πŸš€

@gr2m
Copy link
Member

gr2m commented May 26, 2021

@stoe I see you created https://github.com/stoe/octoherd-dependabot-config, very cool! How did the setup go? Did you use npm init octoherd-script?

@stoe
Copy link
Contributor Author

stoe commented May 26, 2021

@stoe I see you created https://github.com/stoe/octoherd-dependabot-config, very cool! How did the setup go? Did you use npm init octoherd-script?

I ported this locally from an old script before I found out about npm init octoherd-script.

The Go template is via https://github.com/stoe/octoherd-dependabot-config/blob/main/dependabot.go.yml and I only switch the used template via discovered logic:
https://github.com/stoe/octoherd-dependabot-config/blob/70a0396f8b1cd8fc8ff81ca5e870c7b76ea4d357/script.js#L36-L47

@gr2m
Copy link
Member

gr2m commented May 26, 2021

If you like you could submit your script to https://github.com/octoherd/octoherd/discussions/categories/show-and-tell, it might be useful to others! And make sure to install https://github.com/apps/octoherd/, I use it for some upgrade automation via PRs such as octoherd/script-star-or-unstar#6

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants