staged approval customization / api #196948
Replies: 1 comment
-
|
💬 Your Product Feedback Has Been Submitted 🎉 Thank you for taking the time to share your insights with us! Your feedback is invaluable as we build a better GitHub experience for all our users. Here's what you can expect moving forward ⏩
Where to look to see what's shipping 👀
What you can do in the meantime 💻
As a member of the GitHub community, your participation is essential. While we can't promise that every suggestion will be implemented, we want to emphasize that your feedback is instrumental in guiding our decisions and priorities. Thank you once again for your contribution to making GitHub even better! We're grateful for your ongoing support and collaboration in shaping the future of our platform. ⭐ |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
🏷️ Discussion Type
Product Feedback
Body
Thanks for getting out staged publishing. Adding that final check isolated from CI is an important step.
I'd like to implement my own staged approval workflow - for example going through some kind of audit, and then having multiple users sign off, using my own 2fa requirements. I'm fine with being responsible for the security around this - the important part is that it is isolated from CI, which is more easily compromised. If I understand correctly, I can sort of do this if I use a read-write token and send along a generated OTP with the
stage approvecli command. A few problems with this:A few ideas that might help:
One specific implementation would be allowing creating a new staged approval key that is attached to a specific package or to a scope rather than a user. Probably ok if there's only 1 at a time. Existence of this key could then disable approval by any users. Additional IP restrictions like on normal keys might be nice.
Beta Was this translation helpful? Give feedback.
All reactions