GitHub makes app identity more agent-ready
A quiet day for major AI releases, but a useful security shift for anyone letting agents touch repositories and tools.
No stronger source-backed model or platform launch surfaced today. The useful shift is GitHub’s OAuth and GitHub App update: OAuth apps can opt in to expiring access tokens and refresh tokens, and GitHub has released multiple updates aimed at more secure app development. This matters because agent workflows increasingly depend on small connected apps rather than one big assistant. If an agent, connector, or internal tool keeps long-lived access to a repo, the risk is not only bad code, it is stale permission. Treat this as a prompt to audit which GitHub-connected tools still have broad or permanent access.