Skip to content

Automatically revoke GitLab.com PATs discovered by Secret Detection

Proposal

Use existing detection rules for GitLab tokens, and existing post-processing and revocation functionality, to revoke GitLab Personal Access Tokens (and other tokens if possible) whenever they are detected.

Notes:

  1. Work supporting this epic started before this issue and its epic were created and has taken place in various issues. This issue is meant to track its delivery.
  2. This issue concentrates on GitLab.com because existing revocation functionality is only available in GitLab.com. For Self-Managed, see #371659 (closed).

Status

Edited by Connor Gilbert