Movatterモバイル変換


[0]ホーム

URL:


Skip to contentSkip to sidebar
/Blog
Try GitHub CopilotAttend GitHub Universe

Keeping secrets out of public repositories

With push protection now enabled by default, GitHub helps open source developers safeguard their secrets, and their reputations.

|3 minutes
  • Share:

Accidental leaks of API keys, tokens, and other secrets risk security breaches, reputation damage, and legal liability at a mind-boggling scale. In just the first eight weeks of 2024, GitHub has detected over 1 million leaked secrets on public repositories. That’s more than a dozen accidental leaksevery minute.

Since last August, all GitHub cloud users couldopt-in to secret scanning push protection, which automatically blocks commits when a secret is detected. Now, we’ve enabled secret scanning push protection by default for all pushes to public repositories.

What’s changing

This week, we began the rollout of push protection for all users. This means that when asupported secret is detected in any push to a public repository, you will have the option to remove the secret from your commits or, if you deem the secret safe, bypass the block. It might take a week or two for this change to apply to your account; you can verify status and opt-in early incode security and analysis settings.

How will this change benefit me?

Leaked secrets can pose a risk to reputation, revenue, and even legal exposure, which is why GitHub Advanced Security customers scan more than 95% of pushes to private repositories. As champions for the open source community, we believe that public repositories–and your reputation as a coder–are worth protecting, too.

Do I have a choice?

Yes. Even with push protection enabled, you have the choice to bypass the block. Although we don’t recommend it, you can also disable push protection entirely in youruser security settings. However, since you always retain the option to bypass the block, we recommend that you leave push protection enabled and make exceptions on an as-needed basis.

What about private repositories?

If your organization is on theGitHub Enterprise plan, you can addGitHub Advanced Security to keep secrets out of private repositories as well. You’ll also get all of the other features forsecret scanning, along withcode scanning, AI-poweredautofix code suggestions, and other static application security (SAST) features as part of a comprehensive DevSecOps platform solution.

Learn more about secret scanning

GitHub secret scanning guards over 200 token types and patterns from more than 180 service providers, and boasts the industry’s highest precision and lowest rate of false positives.1 Together, we can keep secrets from leaking on public repositories.

Notes


  1. A Comparative Study of Software Secrets Reporting by Secret Detection Tools, Setu Kumar Basak et al., North Carolina State University, 2023. 

Written by

More onopen source

CVE-2025-53367: An exploitable out-of-bounds write in DjVuLibre

DjVuLibre has a vulnerability that could enable an attacker to gain code execution on a Linux Desktop system when the user tries to open a crafted document.

4 trends shaping open source funding—and what they mean for maintainers

Get insights on the latest trends from GitHub experts while catching up on these exciting new projects.

Related posts

Company news

GitHub Availability Report: June 2025

In June, we experienced three incidents that resulted in degraded performance across GitHub services.

News & insights

From pair to peer programmer: Our vision for agentic workflows in GitHub Copilot

AI agents in GitHub Copilot don’t just assist developers but actively solve problems through multi-step reasoning and execution. Here’s what that means.

Company news

GitHub Availability Report: May 2025

In May, we experienced three incidents that resulted in degraded performance across GitHub services.

Explore more from GitHub

Docs

Docs

Everything you need to master GitHub, all in one place.

Go to Docs
The ReadME Project

The ReadME Project

Stories and voices from the developer community.

Learn more
GitHub Copilot

GitHub Copilot

Don’t fly solo. Try 30 days for free.

Learn more
Enterprise content

Enterprise content

Executive insights, curated just for you

Get started

We do newsletters, too

Discover tips, technical guides, and best practices in our biweekly newsletter just for devs.


[8]ページ先頭

©2009-2025 Movatter.jp