Skip to content

[P2] Establish GitHub App private key rotation policy #7

@nbrieussel

Description

@nbrieussel

Actions

  • Enable secret scanning push protection on this repo (Settings → Code security)
  • Annual rotation: generate new key → update secret → verify sync → revoke old key
  • Set up yearly reminder (calendar or scheduled issue-opening workflow)
  • Audit whether WEBHOOK_SECRET is actually used in Actions-only mode

Audit report — section 4

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions