Skip to content

Conversation

@siddavamshi4
Copy link
Contributor

@siddavamshi4 siddavamshi4 commented Jan 2, 2026

##Ref : OPSEXP-3709

This PR reviews the usage of NEXUS_USERNAME / NEXUS_PASSWORD in GitHub Actions workflows and switches to NEXUS_USERNAME_READ_ONLY / NEXUS_PASSWORD_READ_ONLY where elevated privileges are not required.

Copilot AI review requested due to automatic review settings January 2, 2026 14:30
Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates GitHub Actions workflows to use read-only Nexus credentials for security purposes. The changes replace NEXUS_USERNAME and NEXUS_PASSWORD with their read-only equivalents across three workflow files.

  • Updated credential references from write to read-only versions
  • Applied changes to workflows handling Maven deployments, integration tests, and version bumping
  • Improves security posture by limiting credential permissions where appropriate

Reviewed changes

Copilot reviewed 3 out of 3 changed files in this pull request and generated 1 comment.

File Description
.github/workflows/mirror-libreoffice.yml Updated Maven deployment credentials to read-only (requires write access - critical issue identified)
.github/workflows/enteprise.yml Updated Nexus credentials for docker integration and EC2 test workflows to read-only
.github/workflows/bumpVersions.yml Updated Nexus environment variables to read-only for version checking operations

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@siddavamshi4 siddavamshi4 marked this pull request as draft January 2, 2026 14:57
@siddavamshi4 siddavamshi4 changed the title OPSEXP-3709: Use read-only Nexus credentials OPSEXP-3709: Switch to read-only Nexus credentials Jan 5, 2026
@siddavamshi4 siddavamshi4 requested a review from Copilot January 5, 2026 07:20
Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 2 out of 3 changed files in this pull request and generated 2 comments.


💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@siddavamshi4 siddavamshi4 marked this pull request as ready for review January 5, 2026 08:04
Copy link
Member

@gionn gionn left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

  • please revert the enterprise workflow rename as it have unintended consequences in the workflow history (we just live with that since the beginning) and it's out of scope for this pr
  • make sure to test ec2 by adding ec2 label

@siddavamshi4 siddavamshi4 added the ec2-test Triggers ec2 integrations tests label Jan 5, 2026
@siddavamshi4 siddavamshi4 requested review from Copilot and gionn January 5, 2026 14:15
Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 2 out of 2 changed files in this pull request and generated no new comments.


💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@siddavamshi4 siddavamshi4 merged commit 4e22f28 into master Jan 7, 2026
98 checks passed
@siddavamshi4 siddavamshi4 deleted the OPSEXP-3709 branch January 7, 2026 06:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ec2-test Triggers ec2 integrations tests

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants