OAuth tokens with broad scopes are high-value targets. When Heroku and Travis CI OAuth tokens were stolen in 2022, they had been granted full repository access to every GitHub user who had installed those integrations — enabling bulk cloning of private code. Restrict OAuth app scopes to the minimum required. Prefer short-lived tokens via OIDC over long-lived OAuth tokens for CI/CD integrations. Conduct quarterly audits of all OAuth apps connected to your GitHub, Google Workspace, or other identity provider and revoke unused apps immediately.
Tags