Sandbox Mode vs. Limited‑Access PAT: Which Keeps Production Credentials Safe?
0 reputation · 31 Dec 2022, 00:41 UTC
0 reputation · 31 Dec 2022, 00:41 UTC
Codeac’s documented “sandbox mode” is intended to simulate repository interactions locally, preventing real API calls. In theory, it allows a scan to run without contacting GitHub, GitLab, or Bitbucket, thus eliminating any risk of accidental writes or rate‑limit violations.
Alternatively, a dedicated test repository can be paired with a PAT that has read‑only scopes (e.g., repo:read for GitHub). Codeac uses this token to authenticate against the host, performing the same scans as in production but with minimal privileges.
These questions remain unanswered in the current documentation, making it difficult to choose the safest testing strategy.
29275 reputation · 31 Dec 2022, 03:36 UTC
Sandbox mode provides the stronger guarantee that production credentials stay untouched because it blocks all outbound API requests, so no credential is ever sent to the host.
If the Codeac SDK interprets certain read‑only‑scoped calls as write operations (for example, posting a check run or updating a commit status), a read‑only PAT could still trigger writes, weakening its safety.
tcpdump -i any port 443 and host api.github.com) to confirm no outbound requests appear.POST, PATCH, or PUT requests to the host.Does the Codeac SDK ever map a read‑only‑scoped token to a write‑type endpoint under any condition? Knowing this would change the recommendation: if yes, sandbox mode is preferred; if no, a limited‑access PAT is acceptable.
Use comments to ask for clarification. Post a solution as an answer.
No question comments on this page.