Hundreds of GitHub App private keys still valid
🔒 Research from GitGuardian found thousands of exposed GitHub App private keys in public code, with 474 still authenticating as 440 distinct Apps. The leaked keys never expire unless manually revoked, enabling holders to request indistinguishable access tokens and potentially gain wide repository and organizational privileges. Several high-impact keys affected private repositories and organization administration, prompting coordinated disclosures and key rotations.
