Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

Support for KMS

オープン
#982 コメント 1 件 リアクション 4 件 担当者 0 名 GitHub で見る

まだ誰も着手していません。

評価

難易度
5/5
見積もり時間
1週間以上
初心者へのやさしさ
35/100
issue の種類
機能追加
明瞭さ
おおむね明確
活発さ
静か
技術スタック
aws, javascript
領域
backend, security

調査の方向性

まず、GitHub API と Octokit が必要な app 認証フローをサポートしているかを確認し、次に AWS KMS Sign のドキュメントと既存の秘密鍵オプションを確認します。app が鍵のマテリアルを公開したり静的な認証情報を要求したりせずに KMS を利用した署名を使用できれば完了です。

索引モデルが issue の本文から書いたものです。

説明

enhancement

Prerequisites:

  • Is the functionality available in the GitHub UI? If so, please provide a link to information about the feature.

New Feature

Please describe the desired new functionality:

As it stands there are only 2 options for GitHub App private key management:

  1. PRIVATE_KEY - private key is supplied as env variable, least secure
  2. PRIVATE_KEY_PATH - path to the private key, slightly more secure

Given the nature of Safe Settings the corresponding GitHub App is usually highly privileged and its private key is probably the biggest security concern. If that key is compromised the impact can be severe. Therefore, I'd like to have an option to store the key in a Key Management Service (e.g. AWS KMS) so the key material never leaves KMS and there are no static credentials for the safe-settings app to handle. The app would only send the payload (or payload digest) to KMS (sign operation) and get the signature back so it can create a JWT.

主要言語
JavaScript
スター
922
フォーク
227
平均マージ
7日 20時間
マージ済み PR(30日)
1

環境構築

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

github-community-projects/safe-settings のほかの issue

github-community-projects/safe-settings の issue をすべて見る

似ている issue

JavaScript の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。