Push protection is enabled for free users on GitHub
We’ve started the rollout for enabling push protection on all free user accounts on GitHub. This automatically protects you from accidentally committing secrets to public repositories, regardless of...
View ArticleUpdates to security configuration settings for customers in existing grace...
For customers affected by ongoing grace periods, GitHub will automatically update the enable for new repositories security configuration setting for customers not opted out. This change helps you...
View ArticleWorkOS is now a GitHub secret scanning partner
GitHub secret scanning protects users by searching repositories for known types of secrets such as tokens and private keys. By identifying and flagging these secrets, our scans help prevent data leaks...
View ArticleImprovements to security overview insights, secret scanning metrics
Today, we’re releasing a host of new insights to the security overview dashboard, as well as an enhanced secret scanning metrics page. New dashboard insights Third-party alerts integration: Beyond...
View ArticleSecurity overview dashboard: Alert age trends, custom repository and severity...
Starting today, you can take advantage of the new “age” grouping for the alert trends graph and explore enhanced filter options on the security overview dashboard, aimed at improving your analytical...
View ArticleEnablement trends for security products (public beta)
You can now monitor enablement trends for all security products within your GitHub organization. This functionality is designed to give you a detailed overview of how your organization is implementing...
View ArticleSecret scanning AI-generated custom patterns (public beta)
Secret scanning now helps you more easily define custom patterns with GitHub Copilot. As of today, you can leverage AI to generate custom patterns without expert knowledge of regular expressions....
View ArticleSecret scanning and push protection are enabled by default on new public...
All new public repositories owned by personal accounts will now have secret scanning and push protection enabled by default. Pushes to the repository that include known secrets will be blocked by push...
View ArticleManage secret scanning alert dismissal requests with the REST API
With delegated alert dismissal for secret scaning alerts, you can require a review process before alerts are dismissed. This helps you better manage your security risk as well as meet audit and...
View ArticleMergify is now a GitHub secret scanning partner
We have partnered with Mergify to scan for their tokens to help secure our mutual users in public repositories. Mergify’s API key enables users to interact with Mergify’s API in order to retrieve...
View ArticleVolcengine is now a GitHub secret scanning partner
GitHub secret scanning protects users by searching repositories for known types of secrets. By identifying and flagging these secrets, we help protect users from data leaks and fraud associated with...
View ArticleLightspeed is now a GitHub secret scanning partner
GitHub secret scanning protects users by searching repositories for known types of secrets such as tokens and private keys. By identifying and flagging these secrets, our scans help prevent data leaks...
View ArticleSecret scanning expands default pattern and push protection support
GitHub regularly updates the default pattern set for secret scanning with new patterns and upgrades of existing patterns, ensuring your repositories have comprehensive detection for different secret...
View ArticleRemoving hardcoded secrets detection from CodeQL
Starting May 30, 2025, CodeQL will no longer generate code scanning alerts for hardcoded secrets. Instead, we recommend using secret scanning to detect hardcoded secrets in your repositories, which...
View ArticleGitHub Secret Protection and GitHub Code Security for GitHub Enterprise
At GitHub, we believe that investing in the security of your codebases should be straightforward, affordable, and scalable. Today, we’re rolling out standalone GitHub Advanced Security products for...
View ArticleFind secrets exposed in your organization with the secret risk assessment
GitHub is committed to empowering the developer community by helping organizations recognize and address the risks of secret leaks. That’s why we’re launching a new free tool which will help provide...
View ArticleGitHub Advanced Security is here for GitHub Team organizations
At GitHub, we believe that investing in the security of your codebase should be accessible for organizations of all sizes. Starting today, GitHub Team plan customers can purchase GitHub Secret...
View ArticleRenaming secret scanning experimental alerts to generic alerts
Alerts for non-provider patterns and Copilot-detected passwords are now categorized as generic instead of experimental. This change applies to alert filters and the secondary inbox in your alert list...
View ArticleDelegated alert dismissal for code scanning and secret scanning now available...
Keep control over the security posture of your organization with delegated alert dismissal. With this feature, you can require a review process before alerts are dismissed in code scanning and secret...
View ArticleIntroducing GitHub Secret Protection and GitHub Code Security
At GitHub, we believe that investing in the security of your codebases should be straightforward, cost-effective, and accessible for everyone. Today, we’re announcing changes to pricing plans and...
View Article