The KeyGuardRail Brief
Confirmed updates

Integration credentials: GitHub tokens, npm tags, and Loom

This week's updates concern how integrations receive tokens, which release tasks still need a stored credential, and what to do after fixing a credential-disclosure issue. Each applies to a specific system; start with the item your team uses.

Integration tokens · Rollout complete; header retirement scheduled

Check how integrations handle longer GitHub tokens

Announced October 2, 2026. Sources checked October 5, 2026.

New GitHub App installation tokens now use the stateless format by default. They retain the ghs_ prefix but are approximately 520 characters, rather than 40. Permissions, repository scope and the one-hour lifetime are unchanged. GitHub will stop honoring the X-GitHub-Stateless-S2S-Token override header on November 30, 2026.

Who it affects. GitHub App installation integrations on Enterprise Cloud, including data residency and Actions GITHUB_TOKEN. The original rollout notice excludes Enterprise Server. This is not a new personal-access-token lifetime policy.

What remains uncertain. The announcement cannot establish whether your storage, HTTP intermediaries or log redaction accept the longer format. Its approximate length is not a fixed size to validate against.

One next step. Assign the integration owner an end-to-end check of token handling and redaction, treating tokens as opaque strings; after validating both formats, remove any override header before November 30.

Release credentials · Available, opt-in

npm trusted publishers can now manage release tags

Announced September 30, 2026. Sources checked October 5, 2026.

npm added an Allow npm dist-tag permission to trusted publishing configurations. It defaults to off and is separate from direct publishing permission, so a workflow allowed only to stage packages can also receive tag access. Existing token-based tag operations continue to work.

Who it affects. Package maintainers using supported cloud-hosted GitHub Actions, GitLab.com or CircleCI workflows. npm's documentation lists dist-tag support in CLI 11.21.0+ on the 11.x line and 12.2.0+ on the 12.x line; self-hosted runners remain unsupported.

What remains uncertain. A token may still serve other commands or workflows. Matching any configuration with tag permission authorizes the operation, so review overlapping configurations before granting access. There is no mandatory migration date for this permission.

One next step. Ask the release owner to test tag promotion and rollback through one intended trusted publisher, then retire a stored token only after confirming it has no remaining consumers.

Credential rotation · Confirmed advisory; fix available

Loom's security fix includes credential follow-up

Announced October 2, 2026. Sources checked October 5, 2026.

AWS disclosed authentication and outbound-request flaws in Loom, its open-source agent orchestration platform. Version 1.7.0 addresses the token-disclosure and connection-handling issues; its September 20 release predates this advisory. Version 1.6.1 fixed the separate authentication bypass but did not fully fix token disclosure.

Who it affects. Loom deployments below 1.7.0: users with mcp:write or a2a:write access could trigger the outbound-request flaws. The authentication bypass affects versions below 1.6.1 where no identity provider was configured.

What remains uncertain. The advisory does not establish exploitation in your deployment. Restricting integration-management access is an interim measure, not a complete fix. The upgrade alone does not replace credentials that may have been exposed.

One next step. Have the deployment owner coordinate the 1.7.0 upgrade and AWS's post-upgrade steps: rotate integration OAuth2 client secrets and revoke and reissue tokens active during the affected window. If container role credentials were accessed, follow AWS's session-credential and CloudTrail guidance.

Related

Where to go next

GitHub credential inventories and the next SSH changes

Open the free inventory template

See how to get started