Machine identities are the ghosts in our infrastructure. You build an automation tool, issue a key, solve the problem, and move on. The person who set it up leaves the company. The key stays behind, doing its job in the dark, quietly holding the keys to the kingdom.[1]
GitGuardian just published an analysis that proves what anyone who has run an IAM audit already knows: we are absolutely terrible at rotating machine credentials. They pulled half a million exposed RSA keys from their leak dataset, narrowed them down to GitHub-related ones, and found that 474 GitHub App private keys still worked on the API.[1]
That is a 10% hit rate on exposed keys just sitting out in public.[1]
If you haven’t built one, a GitHub App isn’t like an OAuth token. It authenticates as itself. It can act across every repository the installation covers. If it has write permissions, it can modify code. If it has admin permissions, it can take over the organization.[1] Of the compromised keys GitGuardian tested, 207 could write to private repositories, and 44 had full organization admin access.[1]
The most alarming case study in the report belongs to the CDC. A private key for an App used in their Azure CI/CD pipeline leaked into a public repository in April 2025. GitGuardian found it this month, meaning it sat exposed and fully functional for almost a year and a half.[1] It had write access to the repositories mediating interactions with the CDC’s Azure infrastructure. GitGuardian noted it could likely be used to execute arbitrary code within the Azure tenant.[1] They disclosed it on September 4th, and it took two weeks for the credentials to finally get revoked.[1]
Here is what gets me about this whole mess: GitHub App private keys do not expire.[1]
You can set up a personal access token to expire in 30 days. You can force users to re-authenticate. But an App key lives until a human manually deletes it from the configuration screen.[1]
The vast majority of the compromised Apps in the dataset (59%) only had a single installation.[1] These aren’t massive marketplace tools with dedicated security teams. They are internal CI bots, custom workflow automations, and quick scripts someone spun up on a Friday afternoon to solve a deployment headache.[1] The project gets abandoned, the repo gets archived, but the App keeps running.[1]
We talk constantly about zero trust and least privilege, but we treat machine identities like set-and-forget passwords from 2005. A compromised GitHub App is a permanent backdoor into your supply chain.
If you manage a GitHub organization, check your installed Apps today. Look for the ones that haven’t been touched in a year. Delete the ones you don’t recognize. And for the ones you keep, rotate the damn keys.
Sources
[1] https://blog.gitguardian.com/github-app-private-keys-leaked — GitHub App Private Keys: 474 Leaked Keys Still Work