Skip to content

feat(offboard): print GitHub cleanup commands - #6

Open
DerekRoberts wants to merge 8 commits into
mainfrom
feat/offboard-github-cleanup-cmds
Open

DerekRoberts wants to merge 8 commits into
mainfrom
feat/offboard-github-cleanup-cmds

Conversation

@DerekRoberts

@DerekRoberts DerekRoberts commented Sep 30, 2026 •

Copy link
Copy Markdown
Member

Print cleanup commands so leftover access can be removed without a delete mode in the audit.

Summary

  • Findings stay as the report. # notes stay under the finding.
  • Runnable commands (gh, oc, the environment helper) are printed again at column 0 after each person, so a paste hits bash history.
  • CODEOWNERS is OWNER/REPO: path only. Matching lines (other owners) are not printed. Code search does not repeat a file already listed.
  • Org and team DELETE commands are omitted unless --org-owner is set. --org still means which organizations to scan.
  • OpenShift detail is binding -> role (no subject parenthetical; the subject is in the oc line).
  • Direct collaborator DELETE and the environment helper need repository admin. OpenShift uses remove-role-from-user, not deleting the RoleBinding.

Test plan

  • bats offboard/tests (30) and shellcheck --severity=warning in Podman
  • Live report: no DELETE orgs/ unless --org-owner; oc/gh repo lines at column 0

The audit still does not mutate GitHub. Org and team deletes are labeled as needing an owner; direct collaborator and environment reviewer commands are for repository admins.
Use remove-role-from-user so a shared RoleBinding is not deleted. The audit still does not run oc writes.
@DerekRoberts DerekRoberts self-assigned this Sep 30, 2026
Drop the repo admin prefix so the helper path is the whole line. Notes that are not commands start with a hash.
GitHub has no per-reviewer delete, so the report now prints a GET-then-PUT pipeline instead of a helper script.
The GET-then-PUT jq pipeline is not pasteable; the helper is the convenient command.
Indented commands never land in bash history. Notes stay under findings; gh/oc/helper lines are a paste block after each person.
The matching line named other owners. One entry per file; search skips files already listed.
--org already selects which organizations to scan. Membership and teams still list; the DELETE lines need an org owner.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Active

Development

Successfully merging this pull request may close these issues.

1 participant