ministryofjustice / operations-engineering

This repository is home to the Operations Engineering's tools and utilities for managing, monitoring, and optimising software development processes at the Ministry of Justice. • This repository is defined and managed in Terraform
https://user-guide.operations-engineering.service.justice.gov.uk/
MIT License
11 stars 5 forks source link

Investigate moj-operations-engineering-bot tokens #4547

Closed tamsinforbes closed 2 weeks ago

tamsinforbes commented 2 weeks ago

User Need As a member of the operations engineering team, I want to investigate the GitHub personal access tokens in the moj-operations-engineering-bot account, so that we know how and where they are being used to reduce risks, improve clarity, and align with best practices in token management.

Value

Understanding how these tokens are currently used will help us to define how to properly manage them going forward such as significantly reduce security risks by limiting their scope and improving their traceability.

Functional Requirements:

Non-Functional Requirements:

Acceptance Criteria:

Notes:

tamsinforbes commented 2 weeks ago

Documented here