Pass OIDC environment variables to proxy - #1544
Merged
Merged
Conversation
Contributor
There was a problem hiding this comment.
Pull Request Overview
This PR adds support for GitHub Actions OpenID Connect (OIDC) token functionality by passing OIDC environment variables to the Dependabot proxy container. This enables secure authentication with cloud providers using OIDC tokens instead of long-lived credentials.
Key changes:
- Pass
ACTIONS_ID_TOKEN_REQUEST_TOKENandACTIONS_ID_TOKEN_REQUEST_URLenvironment variables to the proxy container - Add comprehensive test coverage for OIDC environment variable forwarding
Reviewed Changes
Copilot reviewed 2 out of 2 changed files in this pull request and generated no comments.
| File | Description |
|---|---|
| src/proxy.ts | Adds OIDC environment variables to proxy container configuration and reorganizes imports |
| tests/proxy-integration.test.ts | Adds integration tests for OIDC environment variable forwarding and reorganizes imports |
Tip: Customize your code reviews with copilot-instructions.md. Create the file or learn how to get started.
JamieMagee
force-pushed
the
jamiemagee/proxy-oidc
branch
from
September 26, 2025 19:52
b84949b to
06024ad
Compare
ryanbrandenburg
approved these changes
Sep 26, 2025
jurre
approved these changes
Sep 30, 2025
JamieMagee
added a commit
to dependabot/cli
that referenced
this pull request
Sep 30, 2025
This change passes the `ACTIONS_ID_TOKEN_REQUEST_TOKEN` and `ACTIONS_ID_TOKEN_REQUEST_URL` from GitHub Actions to the Dependabot proxy container. It's the first part of the feature to allow to proxy to use OIDC federated credentials for authentication to private registries. Eqivalent of github/dependabot-action#1544 References: - [Configuring OpenID Connect in cloud providers][1] - [OpenID Connect reference][2] [1]: https://docs.github.com/en/actions/how-tos/secure-your-work/security-harden-deployments/oidc-in-cloud-providers#requesting-the-jwt-using-environment-variables [2]: https://docs.github.com/en/actions/reference/security/oidc#methods-for-requesting-the-oidc-token
github-merge-queue Bot
pushed a commit
to dependabot/cli
that referenced
this pull request
Sep 30, 2025
This change passes the `ACTIONS_ID_TOKEN_REQUEST_TOKEN` and `ACTIONS_ID_TOKEN_REQUEST_URL` from GitHub Actions to the Dependabot proxy container. It's the first part of the feature to allow to proxy to use OIDC federated credentials for authentication to private registries. Eqivalent of github/dependabot-action#1544 References: - [Configuring OpenID Connect in cloud providers][1] - [OpenID Connect reference][2] [1]: https://docs.github.com/en/actions/how-tos/secure-your-work/security-harden-deployments/oidc-in-cloud-providers#requesting-the-jwt-using-environment-variables [2]: https://docs.github.com/en/actions/reference/security/oidc#methods-for-requesting-the-oidc-token
Merged
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This change passes the
ACTIONS_ID_TOKEN_REQUEST_TOKENandACTIONS_ID_TOKEN_REQUEST_URLfrom GitHub Actions to the Dependabot proxy container.It's the first part of the feature to allow to proxy to use OIDC federated credentials for authentication to private registries.
References: