跳到主内容
@wquguru
精选85GitHub Changelog云与平台

GitHub 新增按令牌类型批量撤销与停用凭据

Credential revocation and deauthorization by token type

原文
发到 X
推荐理由

安全事件响应场景的核心能力升级,企业或组织管理员现在可以按令牌类型精准撤销凭据,避免误伤仍受信任的凭据。建议相关管理员尽快熟悉新 API 与 UI 操作,以提升事件响应效率。

Building on our self-service credential revocation experiences for incident response, you can now take token-type and user-specific actions to deauthorize and revoke user credentials during a security incident. This gives you finer-grained control when responding to a compromise.

基于我们在事件响应中自助式凭证撤销的经验,您现在可以在安全事件期间采取针对令牌类型和用户的具体操作,以取消授权并撤销用户凭证。这使您在应对入侵时拥有更精细的控制。

Previously, credential kill-switch actions applied to all of a user’s credentials at once. Now, enterprise owners, organization admins, and members with the Manage enterprise credentials permission can revoke all tokens of a specific credential type (e.g., Personal access tokens, SSH keys, OAuth app tokens, or GitHub App user access tokens) so you can contain the blast radius of a compromise without revoking credentials that remain trusted.

此前,凭证紧急开关操作会一次性应用于用户的所有凭证。现在,企业所有者、组织管理员以及具有管理企业凭证权限的成员可以撤销特定凭证类型(如个人访问令牌、SSH 密钥、OAuth 应用令牌或 GitHub 应用用户访问令牌)的所有令牌,从而在不撤销仍受信任的凭证的情况下,控制入侵的影响范围。

What’s new

新增功能

  • Token-type-specific bulk deauthorization: Revoke all SSO authorizations for a specific credential type across your enterprise or for a specific user from the UI or the enterprise REST APIs, rather than all types at once.
  • Token-type specific bulk revocation: Delete or revoke all user-level credentials of a specific type. For example, delete all personal access tokens for an individual EMU user without touching their SSH keys.
  • Organization-level parity, in the UI and API: All bulk credential-revocation actions previously available at the enterprise level are now also available at the organization level through both the web UI and the organization REST APIs, enabling incident response for organizations.
  • Auditing and visibility: All deauthorization and revocation actions are captured in the audit log, with notifications to affected users via email.
  • 按令牌类型批量取消授权:通过 UI 或企业 REST API,撤销整个企业或特定用户的特定凭证类型的所有 SSO 授权,而非一次性撤销所有类型。
  • 按令牌类型批量撤销:删除或撤销特定类型的所有用户级凭证。例如,删除单个 EMU 用户的所有个人访问令牌,而不影响其 SSH 密钥。
  • 组织级功能对等,在 UI 和 API 中:之前在企业级别可用的所有批量凭证撤销操作,现在也通过 Web UI 和组织 REST API 在组织级别可用,从而支持组织的事件响应。
  • 审计与可见性:所有取消授权和撤销操作均记录在审计日志中,并通过电子邮件通知受影响的用户。

To learn more, see our documentation around revoking your credentials and how to respond to security incidents in your enterprise.

如需了解更多信息,请参阅我们关于撤销凭证以及如何在企业中应对安全事件的文档。

The post Credential revocation and deauthorization by token type appeared first on The GitHub Blog.

这篇关于按令牌类型撤销凭证和取消授权的文章最初出现在 GitHub 博客上。

更进一步:量化金融体系

看懂新闻只是起点——沿量化金融路径,把它变成能交付的工程能力

进入量化体系 →

相似阅读

另一事件,读法相近