Skip to content

Commit a0ae706

Browse files
cortinicokelset
authored andcommitted
Remove PAT_TOKEN and PAT_USERNAME from CircleCI (#35808)
Summary: This is a cleanup change needed after the CircleCI security incident. We should be using the `Authorization: Bearer` header to trigger `rn-diff-purge` instead of using username & password authentication. Source: https://docs.github.com/rest/reference/repos#create-a-repository-dispatch-event ## Changelog [INTERNAL] - Remove PAT_TOKEN and PAT_USERNAME from CircleCI Pull Request resolved: #35808 Test Plan: I've tested this locally with: ``` curl -X POST https://api.github.com/repos/react-native-community/rn-diff-purge/dispatches \ -H "Accept: application/vnd.github.v3+json" \ -H "Authorization: Bearer [...]" \ -d "{\"event_type\": \"publish\", \"client_payload\": { \"version\": \"test.test.test\" }}" ``` and the run was succesfully fired by react-native-bot: https://github.com/react-native-community/rn-diff-purge/actions/runs/3894079133 Reviewed By: lunaleaps Differential Revision: D42456065 Pulled By: cortinico fbshipit-source-id: 475e9ca80760522cc08bad37d85c5af6727922d3
1 parent 0b6e5b4 commit a0ae706

1 file changed

Lines changed: 1 addition & 1 deletion

File tree

.circleci/config.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -816,7 +816,7 @@ jobs:
816816
command: |
817817
curl -X POST https://api.github.com/repos/react-native-community/rn-diff-purge/dispatches \
818818
-H "Accept: application/vnd.github.v3+json" \
819-
-u "$PAT_USERNAME:$PAT_TOKEN" \
819+
-H "Authorization: Bearer $REACT_NATIVE_BOT_GITHUB_TOKEN" \
820820
-d "{\"event_type\": \"publish\", \"client_payload\": { \"version\": \"${CIRCLE_TAG:1}\" }}"
821821
822822
# -------------------------

0 commit comments

Comments
 (0)