GitHub: Packages support for fine-grained PATs
github.com
github.com
The annoying thing about those is that they force you to set an expiration date, with a maximum of one year from today.
For most of the things I need a PAT for this is a big frustration. I want to set up things like cron jobs that access specific data from specific repos - but I really don't want to have to remember to go and grant them a new token every 365 days.
Older PATs don't have this problem, which means I'm incentivized to continue using those even though they are much less secure because they grant a wider scope.
I want unlimited expiration on finely grained tokens.
My ideal implementation would include both easy revocation and good audit logging - I want to know when the token was last used, but ideally I'd like to know what it was used for and have details of where that request came from (I guess IP address would have to do for that). That way if my token leaks I can revoke it and analyze what happened using the audit log.
I just found this roadmap item relating to this: https://github.com/github/roadmap/issues/599 - "Fine-grained PAT expiry policies for organizations"
It talks about letting organizations set a policy saying "no token lasts more than X months" - I'd love it if this could expand to "... or set a policy that says unlimited tokens are allowed", since then I could set that for my own organizations and stop complaining about this!
I have great sympathy for GitHub’s position and have been in similar ones. Your customer’s security is always, to varying degrees, your problem. I’ve got no doubt that this explicit design choice is in response to support requests, and that it informed by their real-world experiences re attack vectors related to PATs. The problem is that every developer always wants to hit the “no, I’m special, let me do this” button.
This is why I'd like this to be an organizational setting.
When I'm working in a business setting I'm fine with operational overhead like having to rotate keys.
For personal projects I want to be able to set something up with the minimum scoped permissions possible and then leave it running.
There is a miniscule attack vector from using PATs here (maximum someone could do is trigger many GH Actions builds, but they also could do that otherwise), and to rotate the PAT, two people have to coordinate (as the origin repo has tighter permissions), and even though docs exist in the repo for how to rotate them, as it's a rare task people didn't find them the first year (second year is still coming up). For that use-case I'd greatly appreciate if PATs would exist that have a longer/no expiry.
A system that says "sure, you can have a token that doesn't expire if all you are doing is repository_dispatch" would be really useful to me too.
Eventually, something needs to have a non-expiring secret to help identify it.
The more complicated we make this stuff the more chance someone will make a mistake in configuring it and open themselves up to a breach.
Is there a new update? Has it been shipped? It doesn't look like it