Skip to content

Comment on IntelliJ GitHub Plugin leaking credentialsparent

Comments

better even, don’t use never-expiring tokens/credentials that need rotation.

Expiration is still a form of rotation. Also, GitHub doesn't provide never-expiring tokens, all of their tokens have expiration policies and need regular rotation. That doesn't mean that there aren't good reasons (such as in this case vulnerable applications) to manually rotate even before the expiration date.

IIRC, GH classic tokens can never expire.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.