Return warnings in job logs when CI_JOB_TOKEN is used without the secure workflow being enabled
Everyone can contribute. Help move this issue forward while earning points, leveling up and collecting rewards.
Problem to solve
If we could at least warn users and point them to documentation in the job log when CI_JOB_TOKEN is used without the secure workflow-enabled, users can look towards enabling the secure workflow or adopting an alternative.
Proposal
Add warnings in job logs for CI_JOB_TOKEN secure workflow (Mention the token was used, and link to the main token docs page):
Acceptance Criteria
- Only expose to maintainer+ roles or those who have access to the CICD Settings
Edited by 🤖 GitLab Bot 🤖
