Connect private repositories with an access token
Some Git servers don't allow SSH from the internet, which ruled out the deploy key we use for private repositories. You can now connect those repositories over https instead, with an access token from your Git host.
Paste the repository's https URL with the token in it:
https://user:token@host/group/plugin.git
Hosts that take the token on its own work too: https://token@host/group/plugin.git
This works for:
- GitLab deploy tokens and project access tokens
- Bitbucket Cloud repository, project and workspace access tokens
- Bitbucket Data Center personal HTTP access tokens
- GitHub Enterprise personal access tokens (fine-grained or classic)
- Azure DevOps personal access tokens
- Gitea access tokens
- Forgejo access tokens
- Any self-hosted Git server1, including non-standard ports
We test the token as soon as you connect, so a wrong or expired one is refused straight away and nothing is saved. Once connected, it works like any other repository: pick a branch or tag, find the plugins in it, run a review. The token is stored encrypted and is used only to clone your repository for reviews.
Tokens expire, so each token connection has a Replace token button in its settings page. Swap in the new one and the repository keeps its review history.
Mint a token limited to reading the repository: it's all a review needs. Disconnecting removes our copy, but only your Git host can revoke the token itself.
On github.com, private repositories still connect through the MDL Shield app or a deploy key. Access tokens aren't accepted there.
Footnotes
-
The server needs a valid https certificate from a publicly trusted certificate authority. Self-signed certificates, certificates from a private authority, and expired certificates can't be used. ↩