Missing User Warnings
Medium
- Confidence
- 82% confidence
- Finding
- The guide tells users to use a GitHub Personal Access Token as a password during push, but it provides no warning about least privilege, secure storage, or avoiding token exposure in shells, logs, and screenshots. This can lead inexperienced users to create over-scoped tokens or handle them unsafely, increasing the chance of credential leakage and repository compromise.
