Closed
Description
Issue by @so0k
Monday Jan 29, 2018 at 08:24 GMT
Migrated from hootsuite/atlantis#236
Why was it migrated?
Atm, any developer can add pre_get
, pre_init
, pre/post_plan
commands to expose secrets via atlantis.yaml
- as Atlantis requires quite significant permissions, this might be a concern.
Drone used to have a signing step required for the drone.yaml
file, ensuring unauthorized modifications to atlantis.yaml
can be prevented
Activity