App restrictions are now enabled. This means that if someone compromises a Servo GitHub organization member's account, there are fewer ways that they could cause problems :)
If you have any problems with apps accessing the Servo account, please let me know. The process for adding new apps with access to the account is now to request access through the app, and then have an admin approve it at https://github.com/organizations/servo/settings/oauth_application_policy. Thanks for your patience as we make the organization more secure! -edunham On Mon, Jul 24, 2017 at 1:59 PM, Emily Dunham <edun...@mozilla.com> wrote: > Good afternoon spectacular Servo-ists, > > If you use GitHub's OAuth features to interact with the Servo > organization's repos, or if you have SSH keys created prior to 2014 that > you're using on Servo's repos, this message is for you. Otherwise, you can > quit reading here :) > > Since the Servo GitHub organization was created before 2014, it doesn't > have OAuth app restrictions[1] enabled by default. The restrictions > basically prevent members of the organization from handing out permissions > to 3rd-party apps without org owners' (me, Lars, Jack) approval. > > To improve the org's security, we are going to enable these restrictions > this weekend (July 29/30). If you or your bots are using a pre-2014 SSH key > to interact with anything in Servo org, please switch to using a new key > this week so that the app restrictions change doesn't interrupt your > workflow. > > You're welcome to ask any questions about this change here, on IRC, or in > the GitHub issue[2] tracking it. > > *tl;dr If your SSH key quits working for the Servo org on GitHub this > weekend, replace it with one created after March 2014 and everything will > be ok.* > > Have a fantastic Monday, > edunham > > > [1]: https://help.github.com/articles/about-oauth-app-access-restrictions/ > [2]: https://github.com/servo/servo/issues/17766 > _______________________________________________ dev-servo mailing list dev-servo@lists.mozilla.org https://lists.mozilla.org/listinfo/dev-servo