Repository navigation
Switch to native bindings for macOS Keychain #7123
Description
Activity
- added a commit that references this issue
on Jul 24, 2023 - addeddiscussFeature changes that require discussion primarily among the GitHub CLI teamFeature changes that require discussion primarily among the GitHub CLI team
on Jul 24, 2023 - addedcoreThis issue is not accepting PRs from outside contributorsThis issue is not accepting PRs from outside contributorsand removeddiscussFeature changes that require discussion primarily among the GitHub CLI teamFeature changes that require discussion primarily among the GitHub CLI team
on Aug 7, 2023 @YorikSar You are correct in that the prerequisites for this work are now in place. The team is unsure if now is the right time to take on this work as it would be a breaking change and likely require all our users to re-authenticate.
@samcoe Thank you for your reply. I will add code that will convert go-keyring format (prefixed base64-encoded string) to the "new" format (plain data). That would allow to reuse existing token. After that all that user will have to do is authorise
ghto access this value, no reauthentication required.Reacted by Sam Coe- added 3 commits that reference this issue
on Aug 7, 2023 Done. Please see the PR for the additional compatibility code.
Thanks for the new commits! Without having to force people to re-authenticate we are far more interested in merging this work. Unfortunately our team is stretched so thin right now we can't give this work the QA attention it deserves.
I'm going to mark this as blocked for now for us to revisit once we have more bandwidth towards the end of the year.
- addedgh-authrelating to the gh auth commandrelating to the gh auth command
on Oct 3, 2023 - added a commit that references this issue
on Nov 3, 2023 - added a commit that references this issue
on Feb 8, 2024 - added 2 commits that reference this issue
on May 20, 2024 - added a commit that references this issue
on Nov 5, 2024 Re: using
99designs/keyring- the maintenance status of this project is currently unknown and assumed to be unmaintained.Looking for more discussion on this issue to seek alternative solutions.
@mbevc1 mentioned on Jan 19, 2026
Maintained fork: https://github.com/ByteNess/keyring/
Reacted by David Shafer, Lachlan Donald and Alberto Garcia Illera
Prerequisites:
Any reason why you are not using https://github.com/99designs/keyring besides the cgo problem? The zalando one forks a
securitycommand on MacOS, which is not a secure practice really.I have to grant access to the
securitycli for the github auth token access, andsecuritycan then be invoked with any other shell script after that, losing control of who I grant access to those creds.The 99designs lib does not have this problem, as it uses native API-s, so MacOS would prompt me to grant access to
ghonly.Using the
securitycli tool directly opens up people's hosts to malicious shell scripts also being able to use thesecuritycli tool and gaining access to the credentials, partially defeating the purpose of storing those secrets in the keychain.Originally posted by @reegnz in #7023 (comment)