Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Expiration is still a form of rotation. Also, GitHub doesn't provide never-expiring tokens, all of their tokens have expiration policies and need regular rotation. That doesn't mean that there aren't good reasons (such as in this case vulnerable applications) to manually rotate even before the expiration date.


IIRC, GH classic tokens can never expire.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: