How GitHub gave every repository a durable owner
GitHub has over 14,000 repositories across our primary internal GitHub organization. As of early 2025, there were over 11,000 non-archived repositories, the vast majority of which with no clear owner. For repositories attached to production services, we have historically had robust durable ownership, but for repositories with no associated service, there was no reliable way to tell who the owner is.
That gap became a recurring problem during our secret scanning remediation effort: while we could technically rotate a secret, doing so without knowing the repository owner was risky and often disruptive, and we had no clear way to route remediation work. Over the course of a month and a half, we validated ownership for every active repository, archived about 8,000 repositories that were no longer in use, and changed repository creation so that ownership was required from the start.
Our original ownership model
For years, GitHub has been tracking ownership for deployed services through our internal Service Catalog. Each service entry recorded metadata like which repository it lived in, which gave us a mapping from service to repository; the owning team; executive sponsor; and support information.
Here’s an example of the Repo Ownership app’s service ownership entry:
- team: github/repo-ownership-dev
repo: https://github.com/github/repo-ownership
name: repo-ownership
kind: moda
long_name: Repo Ownership
description: Service enforcing repo ownership across the org
maintainer: mrecachinas
exec_sponsor: stephanmiehe
... Having this rich metadata enables service-centric workflows, such as incident response, on-call routing, vulnerability management, and compliance scoping.
This is an extract. The publication continues at the source.
Read the original at the source: https://github.blog/security/application-security/how-github-gave-every-repository-a-durable-owner/
Officially imported this from GitHub’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- GitHub — imported from official source
- Official source
- https://github.blog/security/feed/ RSS
- Imported
- September 15, 2026 20:57
- Versions
- 1 recorded
- Identity
https://github.blog/?p=97373