Repository navigation
Purge token-in-URL git remotes; SSH-only remote policy #69
Copy link
Copy link
Closed
Labels
majorMajor / load-bearing workMajor / load-bearing workrequirements-targetTracked requirements-target item (joint-close)Tracked requirements-target item (joint-close)
Description
Activity
- addedmajorMajor / load-bearing workMajor / load-bearing workrequirements-targetTracked requirements-target item (joint-close)Tracked requirements-target item (joint-close)
on May 16, 2026 - added a parent issue
on May 16, 2026 Policy + audit done in standards#76 (
REMOTE-URL-POLICY.adoc). Audit 2026-05-17: 0 token-in-URL remotes across 20~/devclones. One item remains and is owner-only: rotate the exposedgho_token at github.com/settings/tokens (manual browser action — cannot be automated from here).Progress 2026-05-19 (keeping OPEN):
- No token-in-URL remotes ✓ — audit of ~130
.git/configunder/home/hyperpolymath/devfound 1 offender (repos/file-souphadgho_****in origin); switched to SSH and verified; final re-scan = 0 offenders. - Policy documented ✓ —
REMOTE-URL-POLICY.adocv1.1.0 + governance-reusable.ymlsecurity-policystep (x-access-token:,:gho_,:ghp_,:ghs_,:github_pat_) landed in standards#147. - Token NOT YET rotated — owner-only/external (Claude cannot revoke). Token with prefix
gho_1q9dB2…(was in file-soup origin) must be revoked at https://github.com/settings/tokens.
Remaining for close: token rotation by owner.
- No token-in-URL remotes ✓ — audit of ~130
Closure-ready — all 3 acceptance criteria met (2026-05-20)
Criterion State Where 1. Local SSH switch ✅ DONE 2026-05-19 repos/file-souporigin scrubbed to SSH; estate-wide re-scan = 0 token-in-URL remotes2. Policy + enforcement landed ✅ DONE 2026-05-19 standards#147 MERGED (REMOTE-URL-POLICY.adoc v1.1.0 + governance-reusable.yml SSH-remote policystep that grepsx-access-token:,:gho_,:ghp_,:ghs_,:github_pat_)3. Token rotation ✅ DONE 2026-05-20 Owner revoked GitHub CLI's OAuth app at github.com/settings/applications, which invalidates all tokens it issued. The x-access-token:gho_…URL pattern was the gh CLI's signature. Re-authed viagh auth loginfor a fresh token; the leakedgho_1q9dB2…is now deadReady to close per joint-close convention — owner action.
🤖 Generated with Claude Code
Closing per owner approval — all 3 acceptance criteria met (see prior comment).
- added a commit that references this issue
on May 26, 2026
Metadata
Metadata
Assignees
Labels
majorMajor / load-bearing workMajor / load-bearing workrequirements-targetTracked requirements-target item (joint-close)Tracked requirements-target item (joint-close)
Security: repos/ci had an x-access-token:gho_… token embedded in its origin URL (a 2nd clone of claude-integrations). Scrubbed to SSH this session.
Scope: audit all /dev clones for x-access-token:/PAT-in-URL remotes; switch to SSH; document SSH-only remote policy; ROTATE the exposed gho_ token on GitHub.
Acceptance: no token-in-URL remotes; policy documented in standards; token rotated.
Parent: #66