logo

FYI: Data from deleted GitHub repos may not actually be deleted

ID: 245a8c64-768d-5ca9-b92b-d2a3dbbf14dc

STIX ID: report--245a8c64-768d-5ca9-b92b-d2a3dbbf14dc

Feed Name: The Register (Security)

Threat Score
55/100

Date Published: 2024-07-25

Date Updated: 2026-04-26

Author: Thomas Claburn

...
...

Truffle Security demonstrated that GitHub's fork and dangling-commit behavior (called Cross Fork Object Reference, CFOR) can expose deleted or private repository data — including API keys and private keys — via forks or partial commit-hash enumeration; researchers recovered dozens of valid keys from deleted forks. GitHub says this is documented, intended behavior, while Truffle Security recommends platform changes (isolate fork object pools and provide true permanent deletion) to mitigate the risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.