heroku / heroku/roadmap

Access control for Heroku pipeline especially since Heroku pipelines config vars are accessible by all team members

Open
#343 0 comments 0 reactions 0 assignees View on GitHub
Proposed
Dominant language
No language data
Stars
225
Forks
19
PR merge metrics
No merged PRs in 30d

Description

### Required Terms

- [x] I agree to follow this project's [Code of Conduct](https://github.com/heroku/roadmap/blob/main/CODE_OF_CONDUCT.md)
- [x] I have read and accept the [Salesforce Program Agreement](https://www.salesforce.com/company/program-agreement/)

### What service(s) is this request for?

Heroku Pipeline

### Tell us about what you're trying to solve. What challenges are you facing?

Heroku should secure its pipelines since all members and viewers get access to entire pipeline data that includes the CI variables and confiv vars which are sensitive API keys and tokens for third party like DBs or Jenkins etc.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.