•  


Preventing unauthorized access - GitHub Docs
Skip to main content

Preventing unauthorized access

You may be alerted to a security incident in the media, such as the discovery of the Heartbleed bug , or your computer could be stolen while you're signed in to GitHub.com. In such cases, changing your password prevents any unintended future access to your account and projects.

GitHub requires a password to perform sensitive actions, such as adding new SSH keys, authorizing applications, or modifying team members.

After changing your password, you should perform these actions to make sure that your account is secure:

  • Enable two-factor authentication on your account so that access requires more than just a password. For more information, see " About two-factor authentication ."

  • Add a passkey to your account to enable a secure, passwordless login. Passkeys are phishing-resistant, and they don't require memorization or active management. For more information, see " About passkeys " and " Managing your passkeys ."

  • Review your SSH keys, deploy keys, and authorized integrations and revoke unauthorized or unfamiliar access in your SSH and Applications settings. For more information, see " Reviewing your SSH keys ," " Reviewing your deploy keys ," and " Reviewing and revoking authorization of GitHub Apps ."

  • Verify all your email addresses. If an attacker added their email address to your account, it could allow them to force an unintended password reset. For more information, see " Verifying your email address ."

  • Review your account's security log. This provides an overview on various configurations made to your repositories. For example, you can ensure that no private repositories were turned public, or that no repositories were transferred. For more information, see " Reviewing your security log ."

  • Review the webhooks on your repositories. Webhooks could allow an attacker to intercept pushes made to your repository. For more information, see " About webhooks ."

  • Make sure that no new deploy keys were created. This could enable outside servers access to your projects. For more information, see " Managing deploy keys ."

  • Review recent commits made to your repositories.

  • Review the list of collaborators for each repository.

- "漢字路" 한글한자자동변환 서비스는 교육부 고전문헌국역지원사업의 지원으로 구축되었습니다.
- "漢字路" 한글한자자동변환 서비스는 전통문화연구회 "울산대학교한국어처리연구실 옥철영(IT융합전공)교수팀"에서 개발한 한글한자자동변환기를 바탕하여 지속적으로 공동 연구 개발하고 있는 서비스입니다.
- 현재 고유명사(인명, 지명등)을 비롯한 여러 변환오류가 있으며 이를 해결하고자 많은 연구 개발을 진행하고자 하고 있습니다. 이를 인지하시고 다른 곳에서 인용시 한자 변환 결과를 한번 더 검토하시고 사용해 주시기 바랍니다.
- 변환오류 및 건의,문의사항은 juntong@juntong.or.kr로 메일로 보내주시면 감사하겠습니다. .
Copyright ⓒ 2020 By '전통문화연구회(傳統文化硏究會)' All Rights reserved.
 한국   대만   중국   일본