GitHub can now tell you if you ever leak any secrets in your code

GitHub secret scanning
(Image credit: GitHub)

GitHub’s secret scanning alert feature, which was launched in public beta format in December 2022, is now generally available for free across all public repositories.

In a blog post, the developer platform noted that 70,000 public repositories had turned on secret scanning alerts during the beta, and so the full release will be welcome news to many of developers worldwide.

GitHub says that you can turn on the feature across public repositories that you own to help notify you of leaked secrets in code, issues, description, and comments.

GitHub secret scanning

The feature works with over 100 service providers in the GitHub Partner Program which sees the company notifying users and partners upon detecting leaked secrets. 

“With secret scanning alerts enabled, you’ll now also receive alerts for secrets where it’s not possible to notify a partner - for example, if self-hosted keys are exposed - along with a full audit log of actions taken on the alert," Github noted.

The platform noted an experienced developer who had used the tool to scan 14,000 public GitHub Action repositories, resulting in the finding of more than 1,000 secrets, showing how easy it can be to miss them, thus the significance of the tool.

A support document explains when a developer may want to use the tool:

“If you check a secret into a repository, anyone who has read access to the repository can use the secret to access the external service with your privileges.”

These can include anything from API keys to passwords, authentication tokens, and any other sensitive information. 

‘Secret scanning’ can be found under ‘Settings’ > ‘Code security and analysis’ > ‘Security’, where it can be enabled or disabled.

Craig Hale

With several years’ experience freelancing in tech and automotive circles, Craig’s specific interests lie in technology that is designed to better our lives, including AI and ML, productivity aids, and smart fitness. He is also passionate about cars and the decarbonisation of personal transportation. As an avid bargain-hunter, you can be sure that any deal Craig finds is top value!

Read more
hacker.jpeg
Thousands of GitHub repositories exposed via Microsoft Copilot
Shadowed hands on a digital background reaching for a login prompt.
This worrying Git flaw could lead to users leaking credentials
Data Breach
Thousands of widely-used public workspaces are leaking data
An abstract image of digital security.
Hundreds of GitHub repositories hijacked to trick users into downloading malware
A white padlock on a dark digital background.
GitHub is hiding malware disguised as games, legitimate software
GitHub Webpage
GitHub has a major problem with fake rankings, which could put users at risk of attack
Latest in Security
Webex by Cisco banner on a Chromebook
Cisco warns some Webex users of worrying security flaw, so patch now
Red padlock open on electric circuits network dark red background
AI-powered cyber threats are becoming the biggest worry for businesses everywhere
Woman using iMessage on iPhone
Apple to take legal action against British Government over backdoor request
Red padlock open on electric circuits network dark red background
Aviaton firms hit by devious new polyglot malware
A laptop with a red screen with a white skull on it with the message: "RANSOMWARE. All your files are encrypted."
Major ransomware attack sees Tata Technologies hit - 1.4TB dataset with over 730,000 files allegedly stolen
Image of laptop infected with malware
Ransomware criminals are now sending their demands...by snail mail?
Latest in News
AMD Ryzen 9950X
Ryzen CPUs are the cheapest Zen 5 cores you can buy, but I was surprised to see this AMD 192-core CPUs on the value leaderboard
A hand holding a phone showing the Android Find My Device network
Android's Find My Device can now let you track your friends – and I can't decide if that's cool or creepy
Insta360 X4 360 degree camera without lens protector
Leaked DJI Osmo 360 image suggests GoPro and Insta360 should be worried – here's why
A YouTube Premium promo on a laptop screen
A cheaper YouTube Premium Lite plan just rolled out in the US – but you’ll miss out on these 4 features
Viaim RecDot AI true wireless earbuds
These AI-powered earbuds can also act as a dictaphone with transcription when left in their case
The socket interface of the Intel Core Ultra processor
Intel unveils its most powerful AI PCs yet - new Intel Core Ultra Series 2 processors pack in vPro for lightweight laptops and high-performance workstations alike