# PSA: If you are an owner of a GitHub organization, please review the GitHub Apps installed on your organization (and remove any that are no longer needed)

**URL:** <https://discourse.julialang.org/t/psa-if-you-are-an-owner-of-a-github-organization-please-review-the-github-apps-installed-on-your-organization-and-remove-any-that-are-no-longer-needed/79581>\
**Category:** Community\
**Created:** [April 16, 2022, 8:08pm UTC](https://discourse.julialang.org/t/psa-if-you-are-an-owner-of-a-github-organization-please-review-the-github-apps-installed-on-your-organization-and-remove-any-that-are-no-longer-needed/79581 "2022-04-16T20:08:52Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![dilumaluthge](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/dilumaluthge/32/29283_2.png) [@dilumaluthge](https://discourse.julialang.org/u/dilumaluthge)\
**Post date:** [April 16, 2022, 8:08pm UTC](https://discourse.julialang.org/t/psa-if-you-are-an-owner-of-a-github-organization-please-review-the-github-apps-installed-on-your-organization-and-remove-any-that-are-no-longer-needed/79581/1 "2022-04-16T20:08:52Z")

</div>

If you are the owner of a GitHub organization, please review the list of GitHub Apps that are installed on your organization, and remove any Apps that are no longer needed.

You can access the list of GitHub Apps by going to the following URL: `https://github.com/organizations/$ORGANIZATION_NAME/settings/installations`

For example, the list of GitHub Apps installed on the `JuliaLang` organization is accessible at the [https://github.com/organizations/JuliaLang/settings/installations](https://github.com/organizations/JuliaLang/settings/installations) URL.

For example, if you spot any of the following GitHub Apps on your organization, I would recommend that you uninstall them:

| Name | Explanation |
| --- | --- |
| Julia FemtoCleaner | FemtoCleaner is deprecated. |
| Julia TagBot | The TagBot GitHub App is no longer supported. Please transition to the [TagBot GitHub Action](https://github.com/JuliaRegistries/TagBot). |
| AppVeyor CI | We recommend transitioning to GitHub Actions CI. |
| Travis CI | No longer offers CI for open-source repos. We recommend transitioning to GitHub Actions CI. |

## Asking for a GitHub App to be Reinstalled

On a related note, Viral and I have been performing this review for some of the GitHub organizations in the Julia community. If you notice that a GitHub App has been uninstalled, but you actually do need to keep using that GitHub App, please post in the `#community` channel on the [Julia Slack](https://julialang.org/slack/).

## Motivation

Having unnecessary GitHub Apps installed on your organization increases the attack surface area on your organization. If there is a compromise in one of those Apps, this can lead to an attack on your organization. Just as an example:

> **[Security alert: Attack campaign involving stolen OAuth user tokens issued to...](https://github.blog/news-insights/company-news/security-alert-stolen-oauth-user-tokens/)**
>
> On April 12, GitHub Security began an investigation that uncovered evidence that an attacker abused stolen OAuth user tokens issued to two third-party OAuth integrators, Heroku and Travis-CI, to download data from dozens of organizations, including...
