Securing non-human identities: automated revocation, OAuth, and scoped permissions
…If we are notified that a token has leaked to a public repository, we will automatically revoke the token to prevent it from being used maliciously. For private repositories, GitHub will notify…