Skip to content

Purge token-in-URL git remotes; SSH-only remote policy #69

Description

@hyperpolymath

Security: repos/ci had an x-access-token:gho_… token embedded in its origin URL (a 2nd clone of claude-integrations). Scrubbed to SSH this session.

Scope: audit all /dev clones for x-access-token:/PAT-in-URL remotes; switch to SSH; document SSH-only remote policy; ROTATE the exposed gho_ token on GitHub.

Acceptance: no token-in-URL remotes; policy documented in standards; token rotated.

Parent: #66

Activity

  1. hyperpolymath commented on May 16, 2026

    @hyperpolymath
    OwnerAuthor

    Policy + audit done in standards#76 (REMOTE-URL-POLICY.adoc). Audit 2026-05-17: 0 token-in-URL remotes across 20 ~/dev clones. One item remains and is owner-only: rotate the exposed gho_ token at github.com/settings/tokens (manual browser action — cannot be automated from here).

  2. hyperpolymath commented on May 19, 2026

    @hyperpolymath
    OwnerAuthor

    Progress 2026-05-19 (keeping OPEN):

    • No token-in-URL remotes ✓ — audit of ~130 .git/config under /home/hyperpolymath/dev found 1 offender (repos/file-soup had gho_**** in origin); switched to SSH and verified; final re-scan = 0 offenders.
    • Policy documented ✓ — REMOTE-URL-POLICY.adoc v1.1.0 + governance-reusable.yml security-policy step (x-access-token:, :gho_, :ghp_, :ghs_, :github_pat_) landed in standards#147.
    • Token NOT YET rotated — owner-only/external (Claude cannot revoke). Token with prefix gho_1q9dB2… (was in file-soup origin) must be revoked at https://github.com/settings/tokens.

    Remaining for close: token rotation by owner.

  3. hyperpolymath commented on May 20, 2026

    @hyperpolymath
    OwnerAuthor

    Closure-ready — all 3 acceptance criteria met (2026-05-20)

    Criterion State Where
    1. Local SSH switch ✅ DONE 2026-05-19 repos/file-soup origin scrubbed to SSH; estate-wide re-scan = 0 token-in-URL remotes
    2. Policy + enforcement landed ✅ DONE 2026-05-19 standards#147 MERGED (REMOTE-URL-POLICY.adoc v1.1.0 + governance-reusable.yml SSH-remote policy step that greps x-access-token:, :gho_, :ghp_, :ghs_, :github_pat_)
    3. Token rotation ✅ DONE 2026-05-20 Owner revoked GitHub CLI's OAuth app at github.com/settings/applications, which invalidates all tokens it issued. The x-access-token:gho_… URL pattern was the gh CLI's signature. Re-authed via gh auth login for a fresh token; the leaked gho_1q9dB2… is now dead

    Ready to close per joint-close convention — owner action.

    🤖 Generated with Claude Code

  4. hyperpolymath commented on May 20, 2026

    @hyperpolymath
    OwnerAuthor

    Closing per owner approval — all 3 acceptance criteria met (see prior comment).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    majorMajor / load-bearing workrequirements-targetTracked requirements-target item (joint-close)

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions