build: fetch release notification secrets from secret manager#1196
build: fetch release notification secrets from secret manager#1196
Conversation
Codecov Report
@@ Coverage Diff @@
## master #1196 +/- ##
=========================================
Coverage 79.06% 79.06%
Complexity 1197 1197
=========================================
Files 205 205
Lines 5268 5268
Branches 435 435
=========================================
Hits 4165 4165
Misses 930 930
Partials 173 173 Continue to review full report at Codecov.
|
vam-google
left a comment
There was a problem hiding this comment.
LGTM, but one question about the populate_secrets script.
| # See the License for the specific language governing permissions and | ||
| # limitations under the License. | ||
|
|
||
| set -eo pipefail |
There was a problem hiding this comment.
Is it a script shared by multiple repositories (i.e. was it copied here, or was it written from scratch)? I'm asking mainly from the security perspective (if it has been tested before for a potential secrets "leaks", since it does some non-trivial stuff on them).
There was a problem hiding this comment.
This is the same secret loader in all the java client libraries (managed by templates). The gax repo does not share the same templates as many are related to maven builds and not gradle.
The release reporter now needs secrets from secret manager as the GitHub Magic Proxy is blocked.