Token-type specific credential revocation and de-authorization actions [GA]
- 主要语言
- 没有语言数据
- 星标
- 8.9k
- 派生
- 1.8k
- PR 合并指标
- 30 天内没有已合并 PR
描述
### Value Prop
When a security incident strikes, you can now revoke specific types of credentials—such as all personal access tokens or all SSH keys—without disrupting every other token in your organization or enterprise. Organization admins also gain the same bulk revocation controls that were previously only available to enterprise owners, so you can respond quickly at the level where you actually manage day-to-day access. This gives security teams a faster, more targeted way to contain credential compromise with minimal collateral impact.
### Expected Outcome
Teams responding to credential incidents will spend less time manually hunting down individual tokens and less risk over-revoking credentials that don't need to be touched. By bringing token-type granularity and org-level parity to bulk revocation, GitHub aims to reduce the blast radius of self-serve incident response and help organizations contain threats more efficiently. The result is a more precise, less disruptive security workflow for enterprise members, org admins, and enterprise owners alike.
贡献指南
调研方向
此路线图 issue 描述了针对特定令牌类型的凭据撤销和组织级取消授权,但没有指明任何仓库文件、测试或实现入口。研究需要首先识别相关的 GitHub 安全和访问控制系统;完成的标准是,能够针对所述凭据类型执行有针对性的批量撤销,同时不影响无关凭据。
由索引模型根据 Issue 内容生成。
评估
- 技术栈
- github
- 领域
- authorization, security
- Issue 类型
- 功能
- 难度
- 5/5
- 预计耗时
- 一周以上
- 活跃度
- 活跃
- 描述清晰度
- 需要澄清
- 新手友好度
- 20/100