Approve external addon GitHub for Jira in repos listed under Mozilla's GitHub org
Categories
(mozilla.org :: Github: Administration, task)
Tracking
(Not tracked)
People
(Reporter: Shraddha, Assigned: cknowles)
Details
Hello Team,
Please approve GitHub for Jira addon integration user to below repository:
There are two Service tickets from users who wants to integrate GitHub PR and commits with their Jira project for deployment and for testing development issues.
Please enable on the requested repo.
Below are my answers to the standard questions for this request:
** Which repositories do you want to have access?
- https://github.com/mozilla-mobile/firefox-ios (Public)
- https://github.com/mozilla-sre-deploy/deploy-fakespot
** New org to be added
https://github.com/mozilla-fakespot/
** Is the repository private or public? Public
** Provide link to vendor's description of permissions needed and why
https://github.com/atlassian/github-for-jira/blob/master/README.md#Authorization
** Provide the Install link for a GitHub app
https://marketplace.atlassian.com/apps/1219592/github-for-jira?tab=overview&hosting=cloud
Thank you
Shraddha
| Assignee | ||
Comment 1•1 year ago
|
||
Couple of things.
- you mention the mozilla-fakespot org - but there are no repositories involved there? If the intent is to add the entire org - then note that the current method of adding the data-sync-user (if that's needed) would require you to respond to 1 invitation for every repo in the org - AND any new repos would need additional work to be added.
- You mention public repositories. The current approval from security here mentions that it is only approved for private and internal repos, and requires a conversation with Security to use it with public repos.
I can NI the security folk here - but wanted to make sure I was understanding the request before I went further.
| Reporter | ||
Comment 2•1 year ago
|
||
The data sync user has access to only this repo https://github.com/mozilla-fakespot/FastChat under Fakespot but ill double check
The repos were listed public in Git so if needed to involve security please do so.
Thanks
| Assignee | ||
Comment 3•1 year ago
|
||
OK, We'll need to discuss Fakespot further. I hear we're waiting for specific repos from the original requestor, so once we have those we can work on adding jira to that org.
mozilla-sre-deploy/deploy-fakespot is a private repo in an org where jira is already - so I've added jira to that repo.
And because mozilla-mobile/ios-firefox is a public repo - setting a NI for Clovis/Antony to look and ask questions, and loop in Hal if they need to.
Comment 4•1 year ago
|
||
(In reply to Chris Knowles [:cknowles] from comment #3)
OK, We'll need to discuss Fakespot further. I hear we're waiting for specific repos from the original requestor, so once we have those we can work on adding jira to that org.
mozilla-sre-deploy/deploy-fakespot is a private repo in an org where jira is already - so I've added jira to that repo.
And because mozilla-mobile/ios-firefox is a public repo - setting a NI for Clovis/Antony to look and ask questions, and loop in Hal if they need to.
@chris,
I am good with approving the access for https://github.com/mozilla-mobile/firefox-ios . We still need clarification about the repos for fakespot.
| Assignee | ||
Comment 5•1 year ago
|
||
Joe just provided the immeditate list of repos for fakespot -
https://github.com/mozilla-fakespot/fakespot-workers
https://github.com/mozilla-fakespot/ChromeExtension
https://github.com/mozilla-fakespot/fakespot
https://github.com/mozilla-fakespot/trustwerty
https://github.com/mozilla-fakespot/affiliates-api
https://github.com/mozilla-fakespot/scrapes-api
https://github.com/mozilla-fakespot/ProxyList
https://github.com/mozilla-fakespot/RoboShop
https://github.com/mozilla-fakespot/guard-api
They're all private repos, so per policy we'll get them added to Jira with the Jira team's help.
And I'll update shortly when I poke the mozilla-mobile/firefox-ios to be in Jira
| Assignee | ||
Comment 6•1 year ago
|
||
Shraddha - I've done the needful for the mozilla-mobile/firefox-ios repository. You should be able to configure it in Jira - you know where to find me if there are concerns.
| Assignee | ||
Comment 7•1 year ago
|
||
And Hal just asked me to back it out for further examination. Hal - please advise.
Comment 8•1 year ago
•
|
||
(In reply to Chris Knowles [:cknowles] from comment #5)
Joe just provided the immeditate list of repos for fakespot -
https://github.com/mozilla-fakespot/fakespot-workershttps://github.com/mozilla-fakespot/ChromeExtension
https://github.com/mozilla-fakespot/fakespot
https://github.com/mozilla-fakespot/trustwertyhttps://github.com/mozilla-fakespot/affiliates-api
https://github.com/mozilla-fakespot/scrapes-api
https://github.com/mozilla-fakespot/ProxyListhttps://github.com/mozilla-fakespot/RoboShop
https://github.com/mozilla-fakespot/guard-api
They're all private repos, so per policy we'll get them added to Jira with the Jira team's help.
And I'll update shortly when I poke the mozilla-mobile/firefox-ios to be in Jira
Sounds good to me
Update: my bad - I wasn't current on the status of this bug when I asked for the revert, and was rushing to a meeting. (I was still believing the ask was for an org-wide install.)
Installing on individual private repos is okay. Sorry for the churn, :cknowles
| Assignee | ||
Comment 10•1 year ago
|
||
Oh! No, the specific repo was the firefox-ios repo - which is public. In comment 4 Clovis mentioned that he approved the firefox-ios repo.
The private repos are well covered by the existing approvals.
And we JUST finished adding the private repos in mozilla-fakespot to jira.
So the only thing outstanding is the firefox-ios repo.
In speaking with Shraddha/James they're a little confused by the status there though - the Jira app is only for getting data from GitHub INTO Jira - and doesn't flow the other way (is my understanding from them.). Perhaps further conversations (outside this bug) need to occur to clear things up.
Let me know your decisions on firefox-ios.
| Reporter | ||
Comment 11•1 year ago
|
||
Hi :cfoji and :hwine ,
I will reiterate to what Chris mentioned above " The GitHub for Jira app does not push any Jira data back to Git, it only pulls the PR/commit info into one Jira field (one way) so that the Jira issue owner has the info needed in one screen"
Hence I believe this should not impact whether the request came for public or private repo for this particular app.
Though we do have another app, Unito, which syncs data both ways (Jira<=>Git) but that is another conversation outside of this bug.
I can provide more info around that on a zoom call if needed.
Thanks
Comment 12•1 year ago
|
||
(In reply to Shraddha Patil [:Shraddha Patil] from comment #11)
Hi :cfoji and :hwine ,
I will reiterate to what Chris mentioned above " The GitHub for Jira app does not push any Jira data back to Git, it only pulls the PR/commit info into one Jira field (one way) so that the Jira issue owner has the info needed in one screen"
Hence I believe this should not impact whether the request came for public or private repo for this particular app.
Though we do have another app, Unito, which syncs data both ways (Jira<=>Git) but that is another conversation outside of this bug.
I can provide more info around that on a zoom call if needed.
Thanks
@chris
Given the further explanation. I am approving this request for one direction only permitting data to to be pulled from Git to Jira. If there is any change in the app design in the future which requires bi-directonal flow then it will have to come back to Security to review. I will also update the security notes to reflect these changes.
| Assignee | ||
Comment 13•1 year ago
|
||
Alright - Spoke with Hal as well, just to make sure there was no further whiplash. I've added the firefox-ios in mozilla-mobile to the jira app. Shraddha - you should be good to configure. Let me know if there's any problems.
And Clovis, please update the docs at your earliest convenience.
(And that should close this out ... reopen if there are concerns.)
Comment 14•1 year ago
|
||
(In reply to Shraddha Patil [:Shraddha Patil] from comment #11)
Hi :cfoji and :hwine ,
:Shraddha,
My apologies -- there was some confusion in our handling of this request. The situation of there being 2 different apps to sync data is unusual, and we conflated one with the other.
In addition, we will reiterate the restriction on connecting the Jira app to a GitHub public repo every time. As you can see in Atlassian's documentation, the Jira app could make changes to the GitHub repo. It is only in how you configure the connection with Jira (which is opaque to us) that limits the direction of use. The "check every time on public" was recorded as part of the RRA outcome.
We're updating the docs on our end to make it smoother in the future. AND, it will be helpful if you could split future requests into one for public repos (will need some cross checking), and one for internal or private repos (pre-approved).
Thanks,
--Hal
Description
•