Revoke Forgotten OAuth Apps and Kill Never-Expiring GitHub Tokens Before They Leak
eyishazyer · x · 2026-09-17
Part 3 of a GitHub security thread: revoke unrecognized OAuth apps—every authorization persists until manually pulled, and most people have five or six forgotten ones sitting in Settings → Applications. Quoted part 2: delete never-expiring classic PATs sitting in old config files, the typical cause of accounts compromised months later; replace with scoped fine-grained tokens.
Related event: GitHub Security Tips: Revoke Forgotten Apps and Protect Main Branch(2 posts)→
More from coding & agent
- LangChain Rebuilds LangSmith Trace Filtering for Faster Agent Observability — LangChain · 2026-09-18
- LangChain rebuilds LangSmith trace filtering for faster, more precise agent debugging — LangChain · 2026-09-18
- Dev: The Smartest Model Isn't the Best at Writing Simple, Mergeable Code — timigod · 2026-09-18
- LinkedIn to present a PyTorch-native GPU retrieval engine powering feed and search — PyTorch · 2026-09-18
- Jev + Kimi K3 cascade classifies 100 fraud emails at 96% accuracy for $0.07 — nutlope · 2026-09-17
- AWS compares Bedrock RAG vector stores: OpenSearch vs pgvector vs S3 Vectors — AWS ML Blog · 2026-09-17