Secret scanning: on-demand revocation for GitHub personal access tokens - feedback #139967
Replies: 7 comments
This comment was marked as off-topic.
This comment was marked as off-topic.
This comment was marked as off-topic.
This comment was marked as off-topic.
This comment was marked as off-topic.
This comment was marked as off-topic.
|
hello! Token Metadata Insights: Providing additional metadata about the token, such as usage patterns or last-used timestamps, could help users assess the impact of revocation more effectively before taking action. |
|
The one-click reporting feature for GitHub personal access tokens (PATs) is a great step forward, simplifying remediation and enhancing security. Here's concise feedback: Strengths:
Suggestions:
This feature is impactful but can become indispensable with automation and better admin controls. |
|
ð Discussion Activity Reminder ð This Discussion has been labeled as dormant by an automated system for having no activity in the last 60 days. Please consider one the following actions: 1ïļâĢ Close as Out of Date: If the topic is no longer relevant, close the Discussion as 2ïļâĢ Provide More Information: Share additional details or context â or let the community know if you've found a solution on your own. 3ïļâĢ Mark a Reply as Answer: If your question has been answered by a reply, mark the most helpful reply as the solution. Note: This dormant notification will only apply to Discussions with the Thank you for helping bring this Discussion to a resolution! ðŽ |
|
Very nice feature! |
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
What do you think about secret scanning's new one-click reporting feature?
On-demand revocation for GitHub personal access tokens
You can now report compromised GitHub personal access tokens to GitHub, directly from a secret scanning alert! When you let GitHub know that the secret has been compromised, GitHub will treat the token like a publicly leaked token and revoke it. This change simplifies remediation and makes it more easily actionable.
Soon, weâd love to extend this functionality to additional token issuers â so you disclose compromised credentials and initiate these remediation flows with the issuer, without having to leak the token publicly.
If youâve had a chance to try out the beta feature, we'd love to hear your feedback on: 1) how we can make the feature more useful for you (e.g. organization-level policies for auto-reporting certain types of secrets in private repositories), 2) what token issuers are top of mind for you, 3) what youâd like us to tackle next!
ð Helpful information and some friendly reminders:
All reactions