GitHub App keys can still enable takeovers long after they are forgotten
GitGuardian found 474 still-valid leaked GitHub App keys that can enable repository access and organization takeovers.
GitGuardian reported that GitHub App private keys do not expire and stay usable until manually revoked. Of 4,802 publicly exposed keys collected since 2019, 474 were still valid; 72 percent could read private repository content and 207 could write to it. Forty apps could administer self-hosted runners, 98 could control workflows, and 44 had organization-administration rights. A key for Access Tokens for GitHub Actions, exposed in January 2024, potentially affected about 300 installing organizations, including Civica and Sierra Nevada Corp; BuildBuddy, Crusher.dev, and a CDC-associated app were also named.