Hi,

Good news. The change has been reverted for now:

https://github.community/t/github-api-collaborators-access-changed-today/201259/17

Regards,

Fred


On 16.09.21 14:04, Frederic Gurr wrote:
> Hi,
> 
> A few projects have reported issues with GitHub PRs and the following
> error message in the "Scan Repository" log on their Jenkins instances:
> 
> "Must have push access to view collaborator permission"
> 
> E.g. https://bugs.eclipse.org/bugs/show_bug.cgi?id=576014
> 
> Unfortunately, GitHub has changed their API silently to require admin
> permissions when viewing collaborator permissions.
> 
> There is a related thread in the GitHub community forums here:
> https://github.community/t/github-api-collaborators-access-changed-today/201259
> 
> To quote from a post
> (https://github.community/t/github-api-collaborators-access-changed-today/201259/12):
> "Requiring admin privilege merely for checking whether a user would be
> allowed to merge a pull request seems overbearing. This would go
> directly against the principle of least privilege. This change would
> mean that bots will have to be guarded against accidentally doing any of
> the other catastrophic actions that admin permissions would bring."
> 
> We hope that GitHub reverts this change before the end of the week. In
> the meantime we will investigate possible workarounds for this.
> 
> 
> Regards,
> 
> Fred
> 
> 

-- 
Frederic Gurr
Release Engineer | Eclipse Foundation Europe GmbH

Berliner Allee 47, D-64295 Darmstadt
Handelsregister: Darmstadt HRB 92821
Managing Directors: Gaƫl Blondelle, Mike Milinkovich
_______________________________________________
cross-project-issues-dev mailing list
cross-project-issues-dev@eclipse.org
To unsubscribe from this list, visit 
https://www.eclipse.org/mailman/listinfo/cross-project-issues-dev

Reply via email to