Qodana Cloud CI tokens: long-lived project token vs scheduled rotation for upload credentials
We run Qodana linters in CI and upload results to Qodana Cloud using the QODANA_TOKEN environment variable, one project token per pipeline. The token is stored as a CI secret, and I want to settle on a credential policy before rolling this out to more repositories. The trade-off I cannot resolve from the documentation alone: a long-lived project token is ope