Home / Companies / GitGuardian / Blog / Post Details
Content Deep Dive

GitHub App Private Keys: 474 Leaked Keys Exposed

Blog post from GitGuardian

Post Details
Company
Date Published
Author
Gaetan Ferry
Word Count
2,291
Company Posts That Month
7
Language
English
Hacker News Points
-
Post removed?
No
Summary

GitGuardian found that 474 of 4,802 publicly exposed RSA private keys associated with GitHub Apps still authenticated successfully, representing 440 distinct Apps and demonstrating that leaked keys can remain usable indefinitely because they do not expire automatically. GitHub Apps use these keys to sign JWTs and obtain installation tokens that can access organizations and repositories according to the App’s permissions, making a compromised key capable of exposing private code, modifying repositories, controlling workflows or runners, or administering an organization. Among the affected Apps, 72% had permissions to access repository contents, 207 could write content, and 44 had organization administration privileges, while most had only a single installation and appeared to support internal or forgotten tooling. Case studies involving an Actions-access App, BuildBuddy, the abandoned Crusher.dev project, and a CDC-related App illustrate how leaked keys can create long-lived supply-chain risks affecting both App owners and organizations that installed them. The findings emphasize the need to continuously scan repositories for secrets, promptly revoke or rotate exposed keys, and treat GitHub App private keys as sensitive machine credentials.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 2 451 99 43 -80%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.