Fine-grained PATs can call Enterprise APIs [Public Preview]
- 主要语言
- 没有语言数据
- 星标
- 8.9k
- 派生
- 1.8k
- PR 合并指标
- 30 天内没有已合并 PR
描述
### Value Prop
Today, only PATs (Personal Access Tokens) _Classic_ can interact with the Enterprise account - managing SCIM and users, creating organizations, setting policy, and provisioning self-hosted runners, as popular examples. By switching to fine-grained PATs for these APIs, enterprises get a better least-privilege security posture. With this release, you can use tokens with _just_ enough permission to accomplish the job instead of a PAT (Classic) that requires permission to do _anything_ to your enterprise.
### Expected Outcome
This release trails https://github.com/github/roadmap/issues/793, which establishes the fine-grained permissions model for the enterprise. Because each API must be updated individually to support new permissions, not every single API will be supported at the time of the public preview. We are prioritizing the most popular APIs to ensure that enterprises can replace the highest number of PATs (Classic), and will ship with at least those for the public preview.
These APIs are:
1. Self-hosted runner management
2. Organization creation
3. SCIM support, for platforms that cannot use a GitHub App for provisioning
4. Enterprise team creation and management
5. Budgeting and Licensing management
贡献指南
调研方向
首先审查 roadmap issue 793 以及此处列出的五个 API 领域:自托管运行器、组织创建、SCIM、Enterprise 团队,以及预算和许可。完成的标准是,已确定优先级的 Enterprise APIs 支持细粒度 PAT 权限,使企业能够替换适用的经典 PAT。
由索引模型根据 Issue 内容生成。
评估
- 技术栈
- github
- 领域
- api, authorization, security
- Issue 类型
- 功能
- 难度
- 5/5
- 预计耗时
- 一周以上
- 活跃度
- 停滞
- 描述清晰度
- 需要澄清
- 新手友好度
- 25/100