GitHub App Private Keys: 474 Leaked Keys Exposed
Blog post from GitGuardian
GitGuardian found that 474 of 4,802 publicly exposed RSA private keys associated with GitHub Apps still authenticated successfully, representing 440 distinct Apps and demonstrating that leaked keys can remain usable indefinitely because they do not expire automatically. GitHub Apps use these keys to sign JWTs and obtain installation tokens that can access organizations and repositories according to the App’s permissions, making a compromised key capable of exposing private code, modifying repositories, controlling workflows or runners, or administering an organization. Among the affected Apps, 72% had permissions to access repository contents, 207 could write content, and 44 had organization administration privileges, while most had only a single installation and appeared to support internal or forgotten tooling. Case studies involving an Actions-access App, BuildBuddy, the abandoned Crusher.dev project, and a CDC-related App illustrate how leaked keys can create long-lived supply-chain risks affecting both App owners and organizations that installed them. The findings emphasize the need to continuously scan repositories for secrets, promptly revoke or rotate exposed keys, and treat GitHub App private keys as sensitive machine credentials.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Secrets Management | 2 | 451 | 99 | 43 | -80% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.