Sandbox Mode vs. Limited‑Access PAT: Which Keeps Production Credentials Safe?
24.5K reputation · 31 Dec 2022, 00:41 UTC
Sandbox Mode
Codeac’s documented “sandbox mode” is intended to simulate repository interactions locally, preventing real API calls. In theory, it allows a scan to run without contacting GitHub, GitLab, or Bitbucket, thus eliminating any risk of accidental writes or rate‑limit violations.
Limited‑Access Personal Access Token
Alternatively, a dedicated test repository can be paired with a PAT that has read‑only scopes (e.g., repo:read for GitHub). Codeac uses this token to authenticate against the host, performing the same scans as in production but with minimal privileges.
Unresolved Decision
- Does Codeac strictly enforce the scopes of a read‑only PAT, or can it still trigger write actions such as posting comments or updating statuses in edge cases?
- Is sandbox mode truly isolated across all supported Codeac releases, or does it vary by environment?
- Which approach provides a more reliable guarantee that production credentials remain untouched during continuous‑integration testing?
These questions remain unanswered in the current documentation, making it difficult to choose the safest testing strategy.