github / github/roadmap

Enterprise-level credential visibility - List/Export inventory of all token types [GA]

Ouverte
#1,317 0 commentaires 0 réactions 0 personnes assignées Voir sur GitHub
Enterprise GHES 3.23
Langage dominant
Aucune donnée de langage
Étoiles
8.9k
Forks
1.8k
Métriques de merge des PR
Aucune PR mergée en 30 j

Description

### Value Prop
Enterprise owners and security admins can now export a complete inventory of every credential in their enterprise — including SSH keys, personal access tokens, OAuth app tokens, and GitHub App tokens — from a single view in the UI or via REST API. Each credential entry includes rich metadata like the owner, scopes, creation and expiration dates, last-used timestamp, source IP, and target organizations and repositories. This gives security teams everything they need to assess risk, respond to incidents, and meet compliance requirements on their own terms.

### Expected Outcome
Organizations gain direct, self-serve visibility into all credentials active within their enterprise, eliminating the blind spots that slow down incident response and force reliance on GitHub Support for data they should own. Admins can quickly identify exposed tokens, scope the impact of a security event, and take remediation actions — such as bulk revocations or SSO deauthorizations — without external assistance. This positions GitHub as a meaningful choice for regulated industries and security-conscious enterprises that require strong credential governance.

Guide de contribution

Ouvrir le guide de contribution

Piste de recherche

The issue describes a broad GitHub Enterprise UI and REST API capability for inventorying SSH keys and multiple token types, with metadata and remediation actions. Start by clarifying the required API and UI scope, credential sources, metadata fields, and revocation behavior; done requires a complete enterprise-wide inventory and the stated administrative actions.

Rédigé par le modèle d'indexation à partir du texte de l'issue.

Évaluation

Stack technique
github
Domaine
authentication, authorization, security
Type d'issue
Fonctionnalité
Difficulté
5/5
Temps estimé
Plus d'une semaine
Activité
Calme
Clarté
À clarifier
Accessibilité débutants
25/100

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.