botan icon indicating copy to clipboard operation
botan copied to clipboard

Publicly Visible Coveralls Token

Open FAlbertDev opened this issue 7 months ago • 0 comments

Hi @randombit , my colleagues noticed that Botan's Coveralls repository token is publicly visible in the ci.yml file. It seems sensible to hide this token in a GitHub secure variable, i.e., create a new one and revoke the old one. The token was introduced in #3512. I'm not very familiar with the Coveralls' system, so what do you think?

FAlbertDev avatar Jun 12 '25 12:06 FAlbertDev