github / github/roadmap

Token-type specific credential revocation and de-authorization actions [GA]

未关闭
#1,303 1 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
Copilot Enterprise Copilot for Business Copilot for Individuals Enterprise Free GA GHES 3.23 GitHub Advanced Security (GHAS) Shipped Team
主要语言
没有语言数据
星标
8.9k
派生
1.8k
PR 合并指标
30 天内没有已合并 PR

描述

### Value Prop
When a security incident strikes, you can now revoke specific types of credentials—such as all personal access tokens or all SSH keys—without disrupting every other token in your organization or enterprise. Organization admins also gain the same bulk revocation controls that were previously only available to enterprise owners, so you can respond quickly at the level where you actually manage day-to-day access. This gives security teams a faster, more targeted way to contain credential compromise with minimal collateral impact.

### Expected Outcome
Teams responding to credential incidents will spend less time manually hunting down individual tokens and less risk over-revoking credentials that don't need to be touched. By bringing token-type granularity and org-level parity to bulk revocation, GitHub aims to reduce the blast radius of self-serve incident response and help organizations contain threats more efficiently. The result is a more precise, less disruptive security workflow for enterprise members, org admins, and enterprise owners alike.

贡献指南

打开贡献指南

调研方向

此路线图 issue 描述了针对特定令牌类型的凭据撤销和组织级取消授权,但没有指明任何仓库文件、测试或实现入口。研究需要首先识别相关的 GitHub 安全和访问控制系统;完成的标准是,能够针对所述凭据类型执行有针对性的批量撤销,同时不影响无关凭据。

由索引模型根据 Issue 内容生成。

评估

技术栈
github
领域
authorization, security
Issue 类型
功能
难度
5/5
预计耗时
一周以上
活跃度
活跃
描述清晰度
需要澄清
新手友好度
20/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。