GitHub's secret scanning feature is now even more powerful, covering AWS, Google, Microsoft, and more

GitHub
(Image credit: GitHub)

GitHub’s secret scanning feature has extended beyond the four walls of GitHub to now include validity checks for “select tokens from AWS, Microsoft, Google, and Slack.”

Introduced in January 2023, the functionality is designed to reduce the risk of leaked credentials, like passwords and API keys, by checking whether a token is still active.

This comes around ten months after the Microsoft-owned company promised to add “100+ secret scanning partners.”

GitHub secret scanning

Since the beginning of 2023, the company has made secret scanning and secret scanning push protection free for users of public repositories in a bid to help open source users.

Eligible accounts can enable secret scanning, which now includes more third-party services, via Settings > Code security and analysis > Secret scanning, where the “Automatically verify if a secret is valid by sending it to the relevant partner” option is housed.

GitHub said: “If we can’t accurately detect the validity – this can happen when a token found on GitHub.com belongs to a GitHub Enterprise Server instance – we’ll provide insight on where to look for remediation.”

Looking ahead, the software development platform has committed to supporting more tokens as it expands its partner program. Progress on supported tokens is available to view on a GitHub support page.

Secret scanning works by periodically performing checks in the background, but users can also choose to run a manual check to be sure that they’ve not missed something.

GitHub said in its latest blog post: “Validity checks are another piece of information at your disposal when investigating a secret scanning alert. We hope this feature will provide greater speed and efficiency in triaging alerts and remediation efforts.”

More from TechRadar Pro

Craig Hale

With several years’ experience freelancing in tech and automotive circles, Craig’s specific interests lie in technology that is designed to better our lives, including AI and ML, productivity aids, and smart fitness. He is also passionate about cars and the decarbonisation of personal transportation. As an avid bargain-hunter, you can be sure that any deal Craig finds is top value!

Read more
A graphic showing someone on a tablet working through a supply chain.
Security issue in open source software leaves businesses concerned for systems
A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
These fake GitHub "security alerts" could actually let hackers hijack your account
Shadowed hands on a digital background reaching for a login prompt.
This worrying Git flaw could lead to users leaking credentials
hacker.jpeg
Thousands of GitHub repositories exposed via Microsoft Copilot
An abstract image of digital security.
Hundreds of GitHub repositories hijacked to trick users into downloading malware
Data Breach
Thousands of widely-used public workspaces are leaking data
Latest in Pro
Isometric demonstrating multi-factor authentication using a mobile device.
NCSC gets influencers to sing the praises of 2FA
Sam Altman and OpenAI
OpenAI is upping its bug bounty rewards as security worries rise
Context Windows
Why are AI context windows important?
BERT
What is BERT, and why should we care?
A person holding out their hand with a digital AI symbol.
AI is booming — but are businesses seeing real impact?
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Dangerous new CoffeeLoader malware executes on your GPU to get past security tools
Latest in News
Nintendo Switch 2 Joy-Con up-close from app store
Nintendo's new app gave us another look at the Switch 2, and there's something different with the Joy-Con
cheap Nintendo Switch game deals sales
Nintendo didn't anticipate that Mario Kart 8 Deluxe was 'going to be the juggernaut' for the Nintendo Switch when it was ported to the console, according to former employees
Three angles of the Apple MacBook Air 15-inch M4 laptop above a desk
Apple MacBook Air 15-inch (M4) review roundup – should you buy Apple's new lightweight laptop?
Witchbrook
Witchbrook, the life-sim I've been waiting years for, finally has a release window and it's sooner than you think
Amazon Echo Smart Speaker
Amazon is experimenting with renaming Echo speakers to Alexa speakers, and it's about time
Shigeru Miyamoto presents Nintendo Today app
Nintendo Today smartphone app is out now on iOS and Android devices – and here's what it does