Skip to content

update roles and scopes information#2216

Merged
khorne3 merged 7 commits intomainfrom
katiehorne/tec-357-scm-connectionbroker-list-required-gitlab-roles-as-well-as
Jul 1, 2025
Merged

update roles and scopes information#2216
khorne3 merged 7 commits intomainfrom
katiehorne/tec-357-scm-connectionbroker-list-required-gitlab-roles-as-well-as

Conversation

@khorne3
Copy link
Collaborator

@khorne3 khorne3 commented Jun 26, 2025

This PR:

  • updates GitLab docs to include roles and token scopes information
  • updates the Network Broker doc to link out to tokens info (except for GitHub, since most use the app)

Please ensure

  • A subject matter expert (SME) reviews the content

@netlify
Copy link

netlify bot commented Jun 26, 2025

Don't forget to add /docs at the end of the deploy preview site URL!

Name Link
🔨 Latest commit 0e90820
🔍 Latest deploy log https://app.netlify.com/projects/semgrep-docs-prod/deploys/686288fc02d414000885d047
😎 Deploy Preview https://deploy-preview-2216--semgrep-docs-prod.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@khorne3 khorne3 changed the title Katiehorne/tec 357 scm connectionbroker list required gitlab roles as well as update roles and scopes information Jun 27, 2025
@khorne3 khorne3 marked this pull request as ready for review June 27, 2025 15:26
Copy link
Collaborator

@armchairlinguist armchairlinguist left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This pretty much looks good to me, so I'm going to approve.

I do have one suggestion, though: since we're calling a bit more attention to the use of tokens, I think we should also have a comment that we recommend having the token in the SCM config in the platform unless there's a specific reason that it's better to provide it via the broker.

As far as I understand this aligns with our usual recommendations (although @zyannes can correct me if I'm wrong, as well). Totally viable to consider that in a follow-up PR too since it can be done separately.

@zyannes
Copy link
Member

zyannes commented Jun 27, 2025

Yes I agree with @armchairlinguist. The preferred method is to store the created token in the SCM config instead of the broker.

@khorne3 khorne3 merged commit 3b2dc0a into main Jul 1, 2025
9 checks passed
@khorne3 khorne3 deleted the katiehorne/tec-357-scm-connectionbroker-list-required-gitlab-roles-as-well-as branch July 1, 2025 13:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants