Skip to content

Conversation

@linearbci
Copy link
Collaborator

✨ PR Description

Purpose: Refactor resolver credential handling to prioritize environment variables over client payload values for improved configuration management and security.

Main changes:

  • Modified getRulesResolverUrl and getRulesResolverToken to accept optional payload parameter with ENV-first fallback logic
  • Removed rulesResolverUrl and rulesResolverToken from RuntimeOptions interface, eliminating initialization-time credential setting
  • Added resolverToken and resolverUrl fields to IPayload type for payload-based credential fallback support

CHANGELOG

🔧 Improvements

  • Enhanced credential configuration to prioritize environment variables for better security and deployment flexibility

Generated by LinearB AI and added by gitStream.
AI-generated content may contain inaccuracies. Please verify before using.
💡 Tip: You can customize your AI Description using Guidelines Learn how

@linearbci linearbci added the auto-deploy when exists in PR, will auto make release and auto deploy to prod label Dec 31, 2025
@linearbci linearbci requested a review from MishaKav December 31, 2025 08:06
Copy link

@orca-security-us orca-security-us bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Orca Security Scan Summary

Status Check Issues by priority
Passed Passed Infrastructure as Code high 0   medium 0   low 0   info 0 View in Orca
Passed Passed OSS Licenses high 0   medium 0   low 0   info 0 View in Orca
Passed Passed SAST high 0   medium 0   low 0   info 0 View in Orca
Passed Passed Secrets high 0   medium 0   low 0   info 0 View in Orca
Passed Passed Vulnerabilities high 0   medium 1   low 0   info 0 View in Orca
☢️ The following Vulnerabilities (CVEs) have been detected
PACKAGE FILE CVE ID INSTALLED VERSION FIXED VERSION
high qs ./package-lock.json CVE-2025-15284 6.14.0 6.14.1 View in code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

auto-deploy when exists in PR, will auto make release and auto deploy to prod

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants