GitHub Apps Leave 474 Leaked Keys Live
GitGuardian found 474 publicly leaked GitHub App private keys still authenticating, including 44 apps with full organization-admin access. Because these keys do not expire automatically, forgotten secrets can remain long-lived supply-chain entry points.
GitHub Apps make automation powerful, but non-expiring private keys turn ordinary secret leaks into persistent organizational risk.
- –474 of 4,802 tested keys remained valid, spanning 440 distinct apps
- –72% could read private repositories, while 207 could write to them
- –Compromised apps can affect every repository covered by their installations
- –Developers should store keys in vaults, rotate them regularly, and revoke leaked keys immediately
- –GitHub’s secret scanning must be paired with app-installation and permission inventory
DISCOVERED
1h ago
2026-10-04
PUBLISHED
1h ago
2026-10-04
RELEVANCE
AUTHOR
Better Stack