Help
cancel
Showing results for 
Search instead for 
Did you mean: 
Highlighted
Pilot Lvl 1
Message 1 of 5

Invisible GitHub Apps with write access - How to obtain information?

Solved! Go to Solution.

As an org owner using the get installations (beta) v3 endpoint, I receive information about installations that are not visible in the web UI. Furthermore, the "html_url" returns a 404. (With a visible GitHub App, this url links to the installation information page for that org.) These invisilbe apps have the permissions to write repository content!

 

I've noticed that "29110" is the value for the "app_id" of almost all of these invisible apps. I see this invisible app on almost all of the organizations I have owner access to. My guess is that app 29110 is somehow involved in the operation of GitHub Actions, but I'd love to:

  • get confirmation from someone at GitHub
  • find out how to detect "internal GitHub" apps programatically.

 

Invisible apps with write permissions to source code make me nervous. Has anyone else run into this?

4 Replies
Solution
Pilot Lvl 3
Message 2 of 5

Re: Invisible GitHub Apps with write access - How to obtain information?

Hi @hwine,

 

I can confirm that 29110 is a GitHub app owned by github itself. I don't know why the API doesn't return the right information here, that would be worth asking support.

Pilot Lvl 1
Message 3 of 5

Re: Invisible GitHub Apps with write access - How to obtain information?

Thanks! I'll sleep better this weekend. :D

 

How/where did you determine it was a GitHub owned app? (I'd like to learn how to fish.)

 

Enjoy your weekend!

--Hal

 

P.S. I do have a support ticket in, but don't really expect a reply until next week. Post Universe recovery for much of the staff I assume.

Pilot Lvl 3
Message 4 of 5

Re: Invisible GitHub Apps with write access - How to obtain information?

That fish unfortunately needs to be caught with a very special net, for which one needs to be employed by GitHub. I rarely use that net when helping people on the forum, but this sounded potentially dangerous so I looked in some internal systems to see what this was.

Pilot Lvl 1
Message 5 of 5

Re: Invisible GitHub Apps with write access - How to obtain information?

Update: The API endpoint has been fixed to no longer return these "internal apps". \o/