#tokens
Tagged “tokens”
3 articlesSecurity & supply chain
GitLab's per-user email token can push code and trigger pipelines
Researcher Joe Leon of Aikido Security disclosed that GitLab's incoming-email addresses embed a long-lived, cross-project token that lets anyone holding the address submit patches, run CI/CD and reach the account's secrets.
Sep 26, 2026 · Tomás VegaSecurity & supply chainnpm's stage-only token scope puts a human between CI and the registry
GitHub added a Read and write (stage only) scope to npm granular access tokens. A workflow with the new scope can stage a package version for review, but it cannot publish; a maintainer has to approve the release through 2FA before it goes live.
Sep 19, 2026 · Tomás VegaIncident responseGitHub carves credential revocation into per-token-type actions
GitHub's incident-response tooling now lets enterprise owners and org admins deauthorize or revoke user credentials one token type at a time, in the UI and via API. The blast radius of a bad revoke shrinks, and every action lands in the audit log.
Aug 23, 2026 · Maya Okonkwo