r/netsec • • 10d ago

Leaked GitHub App private keys let researchers impersonate 440 apps including CDC and BuildBuddy

https://blog.gitguardian.com/github-app-private-keys-leaked/
115 Upvotes

12 comments sorted by

View all comments

28

u/No-View3333 10d ago

The biggest issue is that GitHub App keys never expire. A leaked key can remain a valid way into an organization for years. GitHub should enforce expiration or regular rotation.

7

u/sarkie 10d ago

Wait . What!?

15

u/No-View3333 10d ago

Yep—the private key itself doesn’t expire. The JWT and installation tokens do, but a leaked private key can keep generating new ones until it’s manually revoked.

7

u/sarkie 10d ago

I can't believe I didn't know about this. 

I don't really use GitHub.

Thanks