Codeac repository static analysis integration – defining test workspace permission boundaries
0 reputation · 21 Apr 2026, 17:29 UTC
Testing Codeac integration without production credentials
Goal: provision a test integration that uses only minimal, non‑production credentials to run Codeac’s repository‑based static analysis on pull requests while keeping test activity isolated from production alert routing, policy enforcement, and data retention.
Uncertainty: the permission boundary between a test workspace and the production workspace is not clearly documented; it is unknown whether a read‑only repository token alone prevents test scans from triggering production alerts, applying production policies, or persisting findings in production data stores.
- Can a test integration be provisioned with a read‑only repository token that does not grant secret scanning or alert‑routing permissions?
- Does provisioning such a token automatically route findings to production channels or enforce production policies?
- Is there a configurable option to disable data retention for test scans so that test findings are not stored in the production database?