GitHub Token Scanning automatically scans public repositories to check for known token formats. If and when a token is found, it is checked against provider APIs. The provider will then validate the token and send information to the owner about next steps (token cancellation and re-issuing).
Java and .NET support for security vulnerability alerts
We have expanded our security vulnerability alerts to include Java projects using Maven and .NET projects using Nuget. These are in addition to our existing support for JavaScript, Ruby, and Python.
Learn more about security alerts for vulnerable dependencies