Repository navigation
SECURITY
This guide covers security considerations and best practices for using GitHub Commander safely.
What It Is: A token that authenticates you with GitHub API. It has the same access as your GitHub account.
Risks:
- If compromised, attacker can access all your repositories
- Can delete repositories
- Can modify code
- Can access private data
Best Practices:
-
Never Share Your Token
- Don't paste in chat
- Don't email it
- Don't commit it to repositories
- Don't store in plain text files
-
Use Minimal Scopes
- Only grant necessary permissions
- Review scopes regularly
- Revoke unused tokens
-
Short Expiration
- Set 30-90 day expiration
- Rotate tokens regularly
- Don't use permanent tokens
-
Secure Storage
- Token stored in
~/.github-commander/config.json - File permissions should be
600(owner read/write only) - Consider using environment variables (advanced)
- Token stored in
-
Revocation
- Revoke immediately if compromised
- Revoke when no longer needed
- Revoke before changing machines
- Go to GitHub.com → Settings → Developer settings
- Personal access tokens → Tokens (classic)
- Review each token's:
- Scopes
- Expiration date
- Last used date
- Authorized applications
Path: ~/.github-commander/config.json
Contains:
- GitHub token
- Git configuration
- User preferences
- Repository settings
Protection:
-
File Permissions
chmod 600 ~/.github-commander/config.json -
Backup Security
- Encrypt backups
- Don't store in cloud without encryption
- Keep offline copies secure
-
Version Control
- Never commit config file
- Add to
.gitignore - Use template for shared settings
For enhanced security, use environment variables:
export GITHUB_TOKEN="your-token-here"This requires code modification to read from environment.
Review Regularly:
- Collaborators list
- Team memberships
- Organization permissions
- Third-party applications
Least Privilege:
- Grant minimum necessary access
- Use read-only when possible
- Remove access when no longer needed
- Review quarterly
Enable for main branch:
- Require pull request reviews
- Require status checks
- Restrict who can push
- Enable required reviewers
Never Commit:
- API keys
- Passwords
- Certificates
- Private keys
- Configuration secrets
Use Instead:
- GitHub Secrets (for Actions)
- Environment variables
- Secret management tools
- Encrypted secrets files
-
.envfiles (in .gitignore)
Always Use HTTPS:
- GitHub Commander uses HTTPS by default
- Don't disable certificate verification
- Use VPN on public networks
- Be cautious on public Wi-Fi
If using a proxy:
- Ensure proxy is trusted
- Use authenticated proxy
- Configure in system settings
- Verify proxy certificates
Scan for Secrets:
- Use tools like
git-secrets - Scan history before pushing
- Review commits regularly
- Use pre-commit hooks
If Secret Committed:
- Remove from current files
- Rotate the secret immediately
- Remove from git history
- Consider repository rotation if severe
Risks:
- Can contain sensitive data
- Slow down operations
- Exceed GitHub limits
Best Practices:
- Use Git LFS for large files
- Scan before uploading
- Encrypt sensitive large files
- Use external storage when appropriate
Enable on GitHub:
- Required for best security
- Protects against password theft
- Use authenticator app (not SMS)
- Backup recovery codes
Impact on GitHub Commander:
- Personal Access Tokens bypass 2FA
- No additional configuration needed
- Still recommended for overall security
Best Practices:
- Lock workstation when away
- Don't leave application unattended
- Log out when done (if available)
- Use screen timeout
Keep Updated:
- Regularly check for updates
- Update dependencies
- Review changelog for security fixes
- Update promptly when security fixes released
Verify Downloads:
- Download from official sources
- Verify checksums if available
- Check signatures
- Be cautious of modified versions
If Modifying Code:
- Review for security issues
- Don't hardcode secrets
- Validate inputs
- Handle errors securely
- Follow security best practices
Immediate Actions:
- Revoke token on GitHub
- Rotate all secrets that may have been accessed
- Review repository access logs
- Check for unauthorized changes
- Enable 2FA if not already enabled
- Review all connected applications
Immediate Actions:
- Revoke collaborator access
- Review all changes
- Revert unauthorized commits
- Rotate repository secrets
- Check for added files
- Review third-party integrations
Immediate Actions:
- Revoke all GitHub tokens
- Change all passwords
- Review repository access
- Scan for malware
- Rebuild machine if necessary
- Review other accounts
Be Aware Of:
- GDPR requirements
- Data retention policies
- User data handling
- Cross-border data transfer
Regular Audits:
- Review access logs
- Check token usage
- Review permissions
- Audit third-party access
- Document findings
- Lock workstation when away
- Don't share credentials
- Review recent commits
- Check for unauthorized access
- Update application if available
- Review GitHub token scopes
- Review repository collaborators
- Check connected applications
- Review security settings
- Rotate GitHub tokens
- Audit all repositories
- Review and update documentation
- Security training refresh
- Full security audit
- Review all access controls
- Update security policies
- Incident response drill
- git-secrets - Prevent committing secrets
- truffleHog - Find secrets in git history
- GitGuardian - Monitor for secrets
- Snyk - Security scanning
If you find a security vulnerability in GitHub Commander:
- Don't publicize it
- Report it privately
- Allow time for fix
- Follow responsible disclosure
This guide provides general security recommendations. Security is complex and evolving. Always:
- Stay informed about current threats
- Consult security professionals for critical systems
- Follow your organization's security policies
- Use professional judgment