5 ms·
Github already has system to invalidate tokens without storing any hashes themselves https://docs.github.com/en/code-security/secret-scanning/secret-scanning-pa
by devcat 4y ago
Github already has system to invalidate tokens without storing any hashes themselves https://docs.github.com/en/code-security/secret-scanning/secret-scanning-patterns https://docs.github.com/en/code-security/secret-scanning/sec...
- paradite 4y agoYes. This is dependent on some kind of agreement or understanding between SaaS provider and GitHub. I'm thinking of a generic approach which is independent of where you got the secret key and its format.
- devcat 4y agoSame system can be applied for repo owner being pattern provider and getting notified with matches but if i had to guess only enterprise customers might get feature like this