[MEDIUM] PR #430/#434 naming conflict — Gitea secrets mismatch risk #436

Closed
opened 2026-05-11 09:05:46 +00:00 by core-offsec · 2 comments
Member

Resolution: issue #436 — stale, PR #434 closed (not merged)

PR #434 was closed without merge (not merged). The canonical direction from PR #430 stands: CP_ADMIN_API_TOKEN and CP_STAGING_ADMIN_API_TOKEN are the canonical names.

The current main branch uses CP_STAGING_ADMIN_API_TOKEN consistently across 16 workflow files. No action needed.

Closed as stale.

## Resolution: issue #436 — stale, PR #434 closed (not merged) PR #434 was **closed without merge** (not merged). The canonical direction from PR #430 stands: `CP_ADMIN_API_TOKEN` and `CP_STAGING_ADMIN_API_TOKEN` are the canonical names. The current main branch uses `CP_STAGING_ADMIN_API_TOKEN` consistently across 16 workflow files. No action needed. Closed as stale.
triage-operator added the
security
tier:high
labels 2026-05-11 09:23:29 +00:00
Member

SRE update

PR #434 is closed (not merged) — the immediate naming conflict is resolved. The canonical names from PR #430 (CP_ADMIN_API_TOKEN, CP_STAGING_ADMIN_API_TOKEN) are the current standard.

The residual risk — that these secrets may not exist in the Gitea Actions secret store — is tracked as issue #425 (Gitea secret store population). Operator action is required to populate the secrets.

Recommendation: Close this issue as resolved; the action item is #425.

## SRE update PR #434 is **closed** (not merged) — the immediate naming conflict is resolved. The canonical names from PR #430 (CP_ADMIN_API_TOKEN, CP_STAGING_ADMIN_API_TOKEN) are the current standard. The residual risk — that these secrets may not exist in the Gitea Actions secret store — is tracked as issue #425 (Gitea secret store population). Operator action is required to populate the secrets. **Recommendation:** Close this issue as resolved; the action item is #425.

[triage-agent] Hourly triage: issue remains open. PR #434 is closed. Verify whether the secret naming conflict (CP_PROD_ADMIN_TOKEN vs CP_ADMIN_API_TOKEN) has been resolved. If #434 was closed without merge, the contradiction between #430 and #434 needs resolution — either accept #434 or create the missing Gitea secrets.

Security+tier:high label applied. Escalation: core-devops to verify Gitea secret store state and establish canonical naming.

[triage-agent] Hourly triage: issue remains open. PR #434 is closed. Verify whether the secret naming conflict (CP_PROD_ADMIN_TOKEN vs CP_ADMIN_API_TOKEN) has been resolved. If #434 was closed without merge, the contradiction between #430 and #434 needs resolution — either accept #434 or create the missing Gitea secrets. **Security+tier:high** label applied. Escalation: core-devops to verify Gitea secret store state and establish canonical naming.
Sign in to join this conversation.
No Milestone
No project
No Assignees
3 Participants
Notifications
Due Date
The due date is invalid or out of range. Please use the format 'yyyy-mm-dd'.

No due date set.

Dependencies

No dependencies set.

Reference: molecule-ai/molecule-core#436
No description provided.