jenkinsci / jenkinsci/gitlab-branch-source-plugin
Credential GitLab Personnal Access Token should be System and not Global
Open
- Dominant language
- Java
- Stars
- 134
- Forks
- 113
- PR merge metrics
- No merged PRs in 30d
Description
Hello,
We have a security issue with the scope of the credential used in the plugin
Wen we configure the GitLab Server, we have to specify a GitLab Personnal Access Token. This credential have to be in global scope for the plugin to work.
This causes security ploblems because the credential can be used by everyone and everywhere. Indeed it would be a great improvement if the credential can be specified only in System scope (visible only by admins).
Thanks for your help :)
Contributor guide
Assessment
This issue has not been assessed yet.