Skip to content

ci: add dd-octo-sts chainguard policy files#3878

Merged
lloeki merged 1 commit into
masterfrom
lloeki/dd-octo-sts-chainguard
May 13, 2026
Merged

ci: add dd-octo-sts chainguard policy files#3878
lloeki merged 1 commit into
masterfrom
lloeki/dd-octo-sts-chainguard

Conversation

@lloeki
Copy link
Copy Markdown
Member

@lloeki lloeki commented May 12, 2026

Description

Add 4 Chainguard policy files under .github/chainguard/ for the upcoming migration of secrets.GITHUB_TOKEN to DataDog/dd-octo-sts-action.

These policies must be on the default branch before the corresponding workflow changes can use them. They declare which workflow, event, and ref pattern may request which permissions via the dd-octo-sts OIDC token exchange.

Policy files only — no workflow changes. Stacked with #3875.

Reviewer checklist

  • Test coverage seems ok.
  • Appropriate labels assigned.

Add 4 policy files under .github/chainguard/ declaring the
issuer, subject, event, and permission constraints for every
workflow that will be migrated from secrets.GITHUB_TOKEN to
DataDog/dd-octo-sts-action.

These policies must be on the default branch before the
corresponding workflow changes can use them.
@datadog-prod-us1-6
Copy link
Copy Markdown

datadog-prod-us1-6 Bot commented May 12, 2026

Tests

🎉 All green!

❄️ No new flaky tests detected
🧪 All tests passed

🎯 Code Coverage (details)
Patch Coverage: 100.00%
Overall Coverage: 60.67% (-0.05%)

This comment will be updated automatically if new data arrives.
🔗 Commit SHA: 0aa1ff3 | Docs | Datadog PR Page | Give us feedback!

@lloeki lloeki marked this pull request as ready for review May 12, 2026 15:14
@lloeki lloeki requested a review from a team as a code owner May 12, 2026 15:14
@lloeki lloeki merged commit 9b49559 into master May 13, 2026
2115 of 2123 checks passed
@lloeki lloeki deleted the lloeki/dd-octo-sts-chainguard branch May 13, 2026 10:08
@github-actions github-actions Bot added this to the 1.20.0 milestone May 13, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants