Skip to content

fix(skills): catch stateless ghs_ tokens in the secret tripwire - #1177

Merged
aaronjmars merged 1 commit into
mainfrom
fix/ghs-stateless-tripwire
Oct 6, 2026
Merged

aaronjmars merged 1 commit into
mainfrom
fix/ghs-stateless-tripwire

Conversation

@aaronjmars

Copy link
Copy Markdown
Collaborator

What changed

The secret tripwire regex in the email-sending skills now allows _ after the GitHub token prefix:

gh[pousr]_[A-Za-z0-9]{20} -> gh[pousr]_[A-Za-z0-9_]{20}

Only that character class changes. No lines are added or removed, so line numbers stay the same and no catalog regen is needed.

Why

GitHub App installation tokens, including GITHUB_TOKEN in Actions, now use the stateless format ghs_<appid>_<jwt> (GitHub changelog, Oct 2 2026: "Stateless GitHub App installation tokens rolled out"). The old class stopped at the underscore after the app id, so these tokens were not caught and could be sent out in an email body.

How tested

Ran the new pattern with grep -qE and Python re:

  • matches a stateless-shaped token ghs_1234567_eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9.eyJ...sig-_x
  • still matches an old 40-char ghp_ token
  • does not match ghp_short

GitHub App installation tokens (including GITHUB_TOKEN in Actions) now
use the stateless format ghs_<appid>_<jwt>. The tripwire class
gh[pousr]_[A-Za-z0-9]{20} stops at the underscore after the app id, so
these tokens slipped past it. Allow "_" in the class so both the old
40-char tokens and the new stateless tokens are blocked.

Only the character class changes; line counts are unchanged.
@aaronjmars
aaronjmars merged commit 38f6ab8 into main Oct 6, 2026
5 checks passed
@aaronjmars
aaronjmars deleted the fix/ghs-stateless-tripwire branch October 6, 2026 17:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant