GitHub shipped bulk credential revocation for Enterprise. One action cuts off compromised credentials across the entire org during an active incident.
Recent attacks have shown what happens when revocation is slow or incomplete. The Trivy compromise came back for a second round because the first cleanup left at least one credential alive. Incomplete rotation is what keeps attacks going after the initial breach.