Closed Bug 1918054 Opened 7 months ago Closed 6 months ago

Jira app requesting new permissions in GitHub

Categories

(mozilla.org :: Github: Administration, task)

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: cknowles, Assigned: cknowles)

Details

Attachments

(1 file)

Jira app is requesting Read-Only access to "Administration" (twice?)
with the following reasoning:

We’re updating permissions to enable new Atlassian Rovo functionality, and prepare for upcoming Github OAuth changes. These updates are optional if you only use the app to link Github data to Jira (like PRs, commits, and branches).

The orgs requested are:

  • Mozilla
  • Pocket
  • Mozilla-Services
  • Firefox-UX
  • Mozilla-Mobile
  • MDN
  • Mozilla-IT
  • MozillaSocial
  • Mozilla-SRE-Deploy
Flags: needinfo?(cfoji)
Flags: needinfo?(anrivera)

@cknowles, approved. Looks like this already has an approval in https://github.com/MoCo-GHE-Admin/Approved-GHE-add-ons/blob/main/GitHub_Applications.md.

Flags: needinfo?(cfoji)
Flags: needinfo?(anrivera)

The approval there is for the PREVIOUS permissions - this is a change of permission, hence the bug for security to look at. Please confirm that you aren't just repeating the old approval, and are are referring to the new permission set.

per practice, there doesn't need to be an update to the approval list unless there's a DENIAL of permissions, as that deeply complicates managing the apps.

Flags: needinfo?(anrivera)

Thanks for clarifying @cknowles and confirmed that I'm not just repeating the old approval. No concerns with the new permissions - new permission set is approved!

Flags: needinfo?(anrivera)

And permissions are updated. Thank you.

Assignee: nobody → cknowles
Status: NEW → RESOLVED
Closed: 6 months ago
Resolution: --- → FIXED
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: