Enterprise-level credential visibility - List/Export inventory of all token types [GA]
- 主要言語
- 言語のデータがありません
- スター
- 8.9k
- フォーク
- 1.8k
- PR マージ指標
- 30日以内にマージされた PR はありません
説明
### Value Prop
Enterprise owners and security admins can now export a complete inventory of every credential in their enterprise — including SSH keys, personal access tokens, OAuth app tokens, and GitHub App tokens — from a single view in the UI or via REST API. Each credential entry includes rich metadata like the owner, scopes, creation and expiration dates, last-used timestamp, source IP, and target organizations and repositories. This gives security teams everything they need to assess risk, respond to incidents, and meet compliance requirements on their own terms.
### Expected Outcome
Organizations gain direct, self-serve visibility into all credentials active within their enterprise, eliminating the blind spots that slow down incident response and force reliance on GitHub Support for data they should own. Admins can quickly identify exposed tokens, scope the impact of a security event, and take remediation actions — such as bulk revocations or SSO deauthorizations — without external assistance. This positions GitHub as a meaningful choice for regulated industries and security-conscious enterprises that require strong credential governance.
コントリビューションガイド
調査の方向性
The issue describes a broad GitHub Enterprise UI and REST API capability for inventorying SSH keys and multiple token types, with metadata and remediation actions. Start by clarifying the required API and UI scope, credential sources, metadata fields, and revocation behavior; done requires a complete enterprise-wide inventory and the stated administrative actions.
索引モデルが issue の本文から書いたものです。
評価
- 技術スタック
- github
- 領域
- authentication, authorization, security
- issue の種類
- 機能追加
- 難易度
- 5/5
- 見積もり時間
- 1週間以上
- 活発さ
- 静か
- 明瞭さ
- 説明が足りない
- 初心者へのやさしさ
- 25/100