Skip to content

resolve private graph credentials without backend callbacks - #670

Draft
Nishnha wants to merge 1 commit into
mainfrom
nishnha/graph-job-credentials
Draft

Nishnha wants to merge 1 commit into
mainfrom
nishnha/graph-job-credentials

Conversation

@Nishnha

@Nishnha Nishnha commented Oct 10, 2026

Copy link
Copy Markdown
Member

Adds private-dependency credentials to locally captured graph jobs. A caller can reuse an existing checkout and authorized registry/Git access without fetching or completing a separate backend job.

Credentials can come from a local file or an authenticated HTTPS endpoint. The proxy can request JIT Git credentials from the backend while graph-result callbacks stay on the local capture server. Explicit credentials are omitted from captured scenarios; hosted secrets are not expanded as environment references.

Existing invocations retain their behavior unless the new options are supplied. Callers remain responsible for selecting credentials authorized for the graph's repository, branch, and directories.

Validation

Exercised the real Dependabot proxy against controlled authenticated npm and private Git endpoints, including JIT resolution, denied registry access, and local callback capture. The output contains no test secrets, and no graph-result or completion callback reaches the backend.

Co-authored-by: Copilot 223556219+Copilot@users.noreply.github.com

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 513deda8-5d8c-4197-a6bf-a574002242f9
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant