github / github/roadmap

Enterprise-level credential visibility - List/Export inventory of all token types [GA]

未关闭
#1,317 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
Enterprise GHES 3.23
主要语言
没有语言数据
星标
8.9k
派生
1.8k
PR 合并指标
30 天内没有已合并 PR

描述

### Value Prop
Enterprise owners and security admins can now export a complete inventory of every credential in their enterprise — including SSH keys, personal access tokens, OAuth app tokens, and GitHub App tokens — from a single view in the UI or via REST API. Each credential entry includes rich metadata like the owner, scopes, creation and expiration dates, last-used timestamp, source IP, and target organizations and repositories. This gives security teams everything they need to assess risk, respond to incidents, and meet compliance requirements on their own terms.

### Expected Outcome
Organizations gain direct, self-serve visibility into all credentials active within their enterprise, eliminating the blind spots that slow down incident response and force reliance on GitHub Support for data they should own. Admins can quickly identify exposed tokens, scope the impact of a security event, and take remediation actions — such as bulk revocations or SSO deauthorizations — without external assistance. This positions GitHub as a meaningful choice for regulated industries and security-conscious enterprises that require strong credential governance.

贡献指南

打开贡献指南

调研方向

该 issue 描述了 GitHub Enterprise 的一项广泛的 UI 和 REST API 功能,用于盘点 SSH 密钥和多种 token 类型,并提供元数据和修复操作。首先明确所需的 API 和 UI 范围、凭据来源、元数据字段以及撤销行为;完成的要求是实现完整的企业范围盘点和所述的管理操作。

由索引模型根据 Issue 内容生成。

评估

技术栈
github
领域
authentication, authorization, security
Issue 类型
功能
难度
5/5
预计耗时
一周以上
活跃度
冷清
描述清晰度
需要澄清
新手友好度
25/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。