Skip to content

Conversation

@christian-kreuzberger-dtx
Copy link
Collaborator

This scope is apparently not needed for our use-cases, but gives a lot more than we actually need, like executing arbitrary JavaScript code in the Dynatrace Platform.
While this is not a vulnerability in itself, as there is no tool that would allow executing arbitrary JavaScript code right now, we would like to reduce required scopes and permissions to the smallest possible set.

@christian-kreuzberger-dtx christian-kreuzberger-dtx merged commit 2161da8 into main Oct 29, 2025
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants