Home / Companies / GitLab / Blog / Post Details
Content Deep Dive

Why GitLab access tokens now have lifetime limits

Blog post from GitLab

Post Details
Company
Date Published
Author
Hannah Sutor
Word Count
1,490
Company Posts That Month
17
Language
English
Hacker News Points
-
Post removed?
No
Summary

GitLab is implementing changes to access token policies, specifically removing support for non-expiring tokens as of Version 16.0, effective from May 2023. This change means that all personal, group, or project access tokens must now have an expiration date, set to a maximum of 365 days from their creation, to enhance security and minimize risks associated with long-lived credentials. Self-managed GitLab users upgrading from pre-16.0 versions will see tokens without prior expiration dates set to expire one year after their upgrade. To assist in this transition, GitLab offers features such as a token rotation API and email notifications for impending token expirations to help users manage and update their tokens proactively. These changes aim to balance security with usability, acknowledging the challenges of implementing effective security controls, while also providing administrators with tools to customize token lifecycles according to their security needs. Users are encouraged to audit their existing tokens, communicate changes within their teams, and utilize service accounts for automation where applicable, to ensure continued access and functionality within their GitLab environments.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 1 930 136 65 +73%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.