Skip to content

Switch to native bindings for macOS Keychain #7123

Description

@mislav

Prerequisites:

  • our darwin builds should be code-signed and notarized
  • we should enable cgo in our darwin builds

Any reason why you are not using https://github.com/99designs/keyring besides the cgo problem? The zalando one forks a security command on MacOS, which is not a secure practice really.

I have to grant access to the security cli for the github auth token access, and security can then be invoked with any other shell script after that, losing control of who I grant access to those creds.
The 99designs lib does not have this problem, as it uses native API-s, so MacOS would prompt me to grant access to gh only.

Using the security cli tool directly opens up people's hosts to malicious shell scripts also being able to use the security cli tool and gaining access to the credentials, partially defeating the purpose of storing those secrets in the keychain.

Originally posted by @reegnz in #7023 (comment)

Activity

  1. YorikSar commented on Jul 24, 2023

    @YorikSar

    Am I correct in understanding that prerequisites have been covered by #7324? If so, please consider #7743.

  2. added
    discussFeature changes that require discussion primarily among the GitHub CLI team
    on Jul 24, 2023
  3. added
    coreThis issue is not accepting PRs from outside contributors
    and removed
    discussFeature changes that require discussion primarily among the GitHub CLI team
    on Aug 7, 2023
  4. samcoe commented on Aug 7, 2023

    @samcoe
    Contributor

    @YorikSar You are correct in that the prerequisites for this work are now in place. The team is unsure if now is the right time to take on this work as it would be a breaking change and likely require all our users to re-authenticate.

  5. YorikSar commented on Aug 7, 2023

    @YorikSar

    @samcoe Thank you for your reply. I will add code that will convert go-keyring format (prefixed base64-encoded string) to the "new" format (plain data). That would allow to reuse existing token. After that all that user will have to do is authorise gh to access this value, no reauthentication required.

  6. YorikSar commented on Aug 7, 2023

    @YorikSar

    Done. Please see the PR for the additional compatibility code.

  7. vilmibm commented on Aug 15, 2023

    @vilmibm
    Contributor

    Thanks for the new commits! Without having to force people to re-authenticate we are far more interested in merging this work. Unfortunately our team is stretched so thin right now we can't give this work the QA attention it deserves.

    I'm going to mark this as blocked for now for us to revisit once we have more bandwidth towards the end of the year.

  8. BagToad commented on Feb 1, 2025

    @BagToad
    Member

    Re: using 99designs/keyring - the maintenance status of this project is currently unknown and assumed to be unmaintained.

    Looking for more discussion on this issue to seek alternative solutions.

  9. hectorpal commented on Mar 17, 2026

    @hectorpal
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

blockedcoreThis issue is not accepting PRs from outside contributorsenhancementa request to improve CLIgh-authrelating to the gh auth command

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions