github / github/roadmap

Enterprise-level credential visibility - List/Export inventory of all token types [GA]

Offen
#1,317 0 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
Enterprise GHES 3.23
Vorherrschende Sprache
Keine Sprachdaten
Sterne
8.9k
Forks
1.8k
PR-Merge-Kennzahlen
Keine gemergten PRs in 30 T.

Beschreibung

### Value Prop
Enterprise owners and security admins can now export a complete inventory of every credential in their enterprise — including SSH keys, personal access tokens, OAuth app tokens, and GitHub App tokens — from a single view in the UI or via REST API. Each credential entry includes rich metadata like the owner, scopes, creation and expiration dates, last-used timestamp, source IP, and target organizations and repositories. This gives security teams everything they need to assess risk, respond to incidents, and meet compliance requirements on their own terms.

### Expected Outcome
Organizations gain direct, self-serve visibility into all credentials active within their enterprise, eliminating the blind spots that slow down incident response and force reliance on GitHub Support for data they should own. Admins can quickly identify exposed tokens, scope the impact of a security event, and take remediation actions — such as bulk revocations or SSO deauthorizations — without external assistance. This positions GitHub as a meaningful choice for regulated industries and security-conscious enterprises that require strong credential governance.

Beitragsleitfaden

Beitragsleitfaden öffnen

Rechercherichtung

The issue describes a broad GitHub Enterprise UI and REST API capability for inventorying SSH keys and multiple token types, with metadata and remediation actions. Start by clarifying the required API and UI scope, credential sources, metadata fields, and revocation behavior; done requires a complete enterprise-wide inventory and the stated administrative actions.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
github
Bereich
authentication, authorization, security
Issue-Typ
Feature
Schwierigkeit
5/5
Geschätzter Aufwand
Über eine Woche
Aktivitätsstatus
Ruhig
Klarheit
Muss geklärt werden
Anfängerfreundlichkeit
25/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.