{"repo":"tentwentyone/github-org-sso-auth-revoker","free":true,"listed":false,"github":"https://github.com/tentwentyone/github-org-sso-auth-revoker","clone":"git clone https://github.com/tentwentyone/github-org-sso-auth-revoker.git","description":"Enhance GitHub security by revoking unused credentials automatically with TenTwentyOne's GitHub Action","language":"Python","stars":17,"topics":["authentication","github-organization","python","security","sso","tokens"],"license":"MIT","category":"auth-billing-email","readme_excerpt":"Revoke unused GitHub Organization credentials This GitHub Action automates the revocation of unused Personal Access Tokens and SSH keys (credentials), enhancing organizational security by removing unused credentials that haven't been accessed within a specified timeframe. Proactively eliminating these credentials reduces the risk of security breaches and ensures compliance with the organization's security policies. Where Can I Use This Action? This action can only be used in organizations where Single Sign-On (SSO) is enabled. How Does It Work? The action utilizes a GitHub App to authenticate against the GitHub API. It retrieves all associated credentials for the organization and checks the last time they were used. If a credential has not been utilized for the specified number of days, and it is not expired, the action revokes it. Why Should I Use This Action? An increased attack surface results from having unused (but active) credentials within your organization. Revoking these credentials reduces the risk of unauthorized access to your organization. Furthermore, you only need to set it up once, and it will run automatically on a schedule you define, saving you time and effort. How to set up the action in your organization Prerequisites GitHub App 1. Create a GitHub App in the organization where you want to revoke credentials. - Repository permissions: - metadata : read-only - Organization permissions: - administration : read & write - personal access token : read & write -","default_branch":null,"files":null,"tree":[],"storefront":"/r/tentwentyone","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/tentwentyone/github-org-sso-auth-revoker/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}