github / github/roadmap

Enterprise-level credential visibility - List/Export inventory of all token types [GA]

Aperta
#1,317 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub
Enterprise GHES 3.23
Lingua principale
Nessun dato sulla lingua
Stelle
8.9k
Fork
1.8k
Metriche di merge delle PR
Nessuna PR unita negli ultimi 30g

Descrizione

### Value Prop
Enterprise owners and security admins can now export a complete inventory of every credential in their enterprise — including SSH keys, personal access tokens, OAuth app tokens, and GitHub App tokens — from a single view in the UI or via REST API. Each credential entry includes rich metadata like the owner, scopes, creation and expiration dates, last-used timestamp, source IP, and target organizations and repositories. This gives security teams everything they need to assess risk, respond to incidents, and meet compliance requirements on their own terms.

### Expected Outcome
Organizations gain direct, self-serve visibility into all credentials active within their enterprise, eliminating the blind spots that slow down incident response and force reliance on GitHub Support for data they should own. Admins can quickly identify exposed tokens, scope the impact of a security event, and take remediation actions — such as bulk revocations or SSO deauthorizations — without external assistance. This positions GitHub as a meaningful choice for regulated industries and security-conscious enterprises that require strong credential governance.

Guida per i contributori

Apri la guida per i contributori

Direzione di ricerca

The issue describes a broad GitHub Enterprise UI and REST API capability for inventorying SSH keys and multiple token types, with metadata and remediation actions. Start by clarifying the required API and UI scope, credential sources, metadata fields, and revocation behavior; done requires a complete enterprise-wide inventory and the stated administrative actions.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Valutazione

Stack tecnologico
github
Ambito
authentication, authorization, security
Tipo di issue
Funzionalità
Difficoltà
5/5
Tempo stimato
Più di una settimana
Stato di attività
Tranquilla
Chiarezza
Da chiarire
Idoneità per principianti
25/100

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.