<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Github on Kuldeep Pisda</title><link>https://kdpisda.in/tag/github/</link><description>Recent content in Github on Kuldeep Pisda</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 07 Oct 2026 08:30:00 +0530</lastBuildDate><atom:link href="https://kdpisda.in/tag/github/index.xml" rel="self" type="application/rss+xml"/><item><title>GitHub App Installation Tokens Are Now About 520 Characters. The Bugs Will Be in Your Redaction Rules</title><link>https://kdpisda.in/github-app-stateless-installation-tokens-520-chars/</link><pubDate>Wed, 07 Oct 2026 08:30:00 +0530</pubDate><guid>https://kdpisda.in/github-app-stateless-installation-tokens-520-chars/</guid><description>&lt;p&gt;If a system of yours validates, stores, forwards or redacts GitHub App installation tokens, the format changed under it this year, and on November 30, 2026 the last switch for undoing that goes away. GitHub&amp;rsquo;s &lt;a href="https://github.blog/changelog/2026-10-02-stateless-github-app-installation-tokens-rolled-out"&gt;changelog for October 2&lt;/a&gt; says the staged rollout that began on April 27 is complete. Newly minted installation tokens are now &lt;code&gt;ghs_APPID_JWT&lt;/code&gt;, about 520 characters long instead of 40.&lt;/p&gt;
&lt;p&gt;The part worth a closer look is not minting. Minting returns the token and your client carries on. The breakage lives in every place that holds the token afterwards, and the nastiest case does not throw.&lt;/p&gt;</description></item></channel></rss>