Skip to content

Drop ENV GITHUB_TOKEN="" from the Dockerfile - #26

Merged
dmccoystephenson merged 1 commit into
mainfrom
feature/drop-dockerfile-github-token-env
Sep 25, 2026
Merged

dmccoystephenson merged 1 commit into
mainfrom
feature/drop-dockerfile-github-token-env

Conversation

@dmccoystephenson

Copy link
Copy Markdown
Member

Summary

  • The ENV GITHUB_TOKEN="" line is removed from Dockerfile. It tripped the SecretsUsedInArgOrEnv Dockerfile build check that docker/build-push-action@v7 surfaces, because the check matches on the variable name.
  • No behavior change results: GitHubService reads the token with System.getenv("GITHUB_TOKEN") and guards on token != null && !token.isEmpty(), so an unset variable takes the same anonymous-access path as an empty one. docker-entrypoint.sh never references GITHUB_TOKEN, and the token is still supplied at container start by docker-compose.yml (GITHUB_TOKEN=${GITHUB_TOKEN:-}) and .env.
  • The GITHUB_TOKEN row of the Docker environment variables table in CONFIG.md now lists the image default as (unset) instead of (empty), matching the TRACE_USAGE_REPORTING/DO_NOT_TRACK rows.
  • A CHANGELOG.md [Unreleased] → Fixed entry records the change.

Closes #25

Test plan

  • mvn test locally — 84 tests run, 0 failures, 0 errors, 1 skipped (no Java source changed)
  • CI build job green
  • CI docker-build job green (builds the image and runs docker-entrypoint-test.sh), with no SecretsUsedInArgOrEnv annotation on the run

Deferred issues

This PR description was drafted during a Gardener session (https://github.com/Stephenson-Software/gardener).

🤖 Generated with Claude Code


drafted by Claude on behalf of Daniel Stephenson

The empty default tripped the SecretsUsedInArgOrEnv build check that
docker/build-push-action@v7 surfaces. GitHubService treats an unset
token the same as an empty one, so behavior is unchanged; CONFIG.md now
lists the image default as unset.

Closes #25

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@dmccoystephenson

Copy link
Copy Markdown
Member Author

Self-review rubric (performed inline in the same session; not an independent review):

  • Scope: PASS — three files, each required by Dockerfile ENV GITHUB_TOKEN="" now trips the SecretsUsedInArgOrEnv build check surfaced by build-push-action v7 #25's suggested resolution (Dockerfile line removed, CONFIG.md default cell, CHANGELOG.md entry); no unrelated churn.
  • Tests-new: PASS (n/a) — no new public method; no Java source changed.
  • Tests-fix: PASS — the regression signal for Dockerfile ENV GITHUB_TOKEN="" now trips the SecretsUsedInArgOrEnv build check surfaced by build-push-action v7 #25 is the docker-build job's Dockerfile build-check annotation, compared empirically rather than by reasoning: main run 35458657351 reports SecretsUsedInArgOrEnv ... (ENV "GITHUB_TOKEN") docker-build: Dockerfile#25; PR head run 36118195375 reports only the unrelated ubuntu-latest migration notice. A stash-and-run Java test is not applicable because no Java behavior changed.
  • Sibling structure: PASS — the CONFIG.md row now uses (unset), the same wording as the TRACE_USAGE_REPORTING/DO_NOT_TRACK rows for variables the image does not declare.
  • Sibling renames: PASS (n/a) — nothing renamed.
  • Docs: PASS — CONFIG.md Docker table updated; COMMANDS.md, USER_GUIDE.md and README.md only describe exporting GITHUB_TOKEN and state no image default, so they stay accurate; CHANGELOG.md [Unreleased] → Fixed updated.
  • Issue resolution: PASS — every item in Dockerfile ENV GITHUB_TOKEN="" now trips the SecretsUsedInArgOrEnv build check surfaced by build-push-action v7 #25's suggested resolution is applied.
  • CI: PASS — build and docker-build green on the head SHA (the latter builds the image and runs docker-entrypoint-test.sh); mvn test locally ran 84 tests, 0 failures, 1 skipped.
  • Config-doc parity: PASS (n/a) — no property keys added or changed.
  • Command-doc parity: PASS (n/a) — no CLI flag, system property or endpoint changed.
  • Package placement: PASS (n/a) — no Java classes added.
  • No credential leakage: PASS — the change removes an ENV declaration only; nothing new logs or persists the token.

Dockerfile:25 — behavior note: GitHubService guards on token != null && !token.isEmpty(), so an unset GITHUB_TOKEN takes the same anonymous path the empty default did, and docker-compose.yml still passes GITHUB_TOKEN=${GITHUB_TOKEN:-} into the container.

Out-of-diff observation: both jobs carry a notice that ubuntu-latest moves to Ubuntu 26 from 2026-10-19. It is informational and outside #25's scope.

Do-not-auto-merge paths: none matched (no .github/workflows/*, pom.xml, application*.properties, or >50-line deletions).

This review was drafted during a Gardener session (https://github.com/Stephenson-Software/gardener).


drafted by Claude on behalf of Daniel Stephenson

@dmccoystephenson
dmccoystephenson merged commit 2bf18d6 into main Sep 25, 2026
2 checks passed
@dmccoystephenson
dmccoystephenson deleted the feature/drop-dockerfile-github-token-env branch September 25, 2026 09:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Dockerfile ENV GITHUB_TOKEN="" now trips the SecretsUsedInArgOrEnv build check surfaced by build-push-action v7

1 participant