TL;DR: GitHub environments concentrate machine users, PATs, SSH keys, apps, and secrets in a single collaboration surface, making stale identities, unrotated credentials, and over-permissive integrations the main governance risks according to Oasis Security. The control problem is not automation itself but visibility into what exists, who can use it, and when access should expire.
Editorial analysis by NHI Mgmt Group, based on content published by Oasis Security: “Enhancing Github Security with Oasis”.
Key questions
Q: What breaks when GitHub NHIs are not inventoried?
A: Teams lose the ability to tell which machine users, tokens, keys and apps still exist, so stale access persists unnoticed.
Q: Why do unrotated GitHub credentials increase supply chain risk?
A: Unrotated credentials preserve access long after the original workflow changes, which means an old token or key can still reach repositories, secrets or automation paths.
Q: What do teams get wrong when reviewing permissions for installed GitHub apps?
A: Teams often focus on whether an app is useful instead of whether its permissions are proportionate.
Practitioner guidance
- Inventory every GitHub NHI Discover machine users, PATs, SSH keys, GitHub Apps, OAuth Apps and repository secrets in one ownership model, then assign a business owner and expiry expectation to each one.
- Enforce secret rotation by lifecycle event Rotate or revoke credentials when the underlying workflow, team, vendor or application changes, rather than waiting for informal cleanup cycles to catch them.
- Review third-party app grants for least privilege Validate that each GitHub App or OAuth App still has a business purpose, a current owner and the narrowest permissions needed for the workflow it supports.
Bottom line: GitHub's security problem is not automation itself but unmanaged non-human identities that persist beyond their intended use.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
GitHub has become an identity system, not just a developer platform. The article shows that machine users, PATs, SSH keys, apps and secrets all live in one operational surface, which means governance has to treat GitHub as a non-human identity control plane. The practical consequence is that ownership, scope and expiry matter as much as code access itself.
A few things that frame the scale:
- 92% of organisations expose NHIs to third parties, raising concerns about supply chain security, according to the Ultimate Guide to NHIs.
A question worth separating out:
Q: How should organisations govern third-party access in GitHub?
A: They should treat every external integration as a managed identity with ownership, scope, expiry and revocation criteria. The key is to combine access review with lifecycle offboarding so that OAuth Apps, GitHub Apps and other connectors do not persist beyond their intended use.
👉 Read our full editorial: GitHub NHI governance needs visibility, rotation, and app control